re: resolve ABI verification provenance defects

This commit is contained in:
alex 2026-09-10 00:53:14 -04:00
parent 93e2166217
commit 3e850a4a88
47 changed files with 33080 additions and 3 deletions

View file

@ -21,7 +21,7 @@
"path": "/home/alex/sots-re" "path": "/home/alex/sots-re"
} }
}, },
"checkpoint": "campaign/runtime/checkpoints/research-completion-abi-1340cf6a2a12b704e5cd048e.json", "checkpoint": "campaign/runtime/checkpoints/research-completion-abi-ed14042366e407a5dc26e7a1.json",
"dependencies": [ "dependencies": [
"controls-bootstrap" "controls-bootstrap"
], ],

View file

@ -0,0 +1,23 @@
{
"actor": "research ABI surprise resolver",
"artifacts": [
{
"path": "verify/results/research-completion-abi-correction-verifier/report-run-5bd0e537bb0c4c4f43987ac1.md",
"sha256": "c33ce30e6bb907aa4140b287afc9198bd503e9da179ff3adb8921ca3ba1b87fc"
},
{
"path": "verify/results/research-completion-abi-correction-verifier/run-ee78b8773688ca09f8046e21/manifest.json",
"sha256": "50aa35e22432b153d14dbd6a5cced3ce0ac8826c79b56f500a0ce96a32619393"
}
],
"basis": "aaddeb76f74bbd1a43671f882770ec84a7d690b4060d060ef1a68f918e8edbb0",
"contract": "research-completion-abi",
"id": "070383fd013a0e4b1a2ef5e0",
"model": "openai/gpt-6-astra",
"next_action": "Inspect raw exact/wide streams and helper source, then record scoped Astra resolutions for the two open surprises.",
"role": "resolver",
"schema": "sots-checkpoint/1",
"session": "run-daefd1b77558f324ae730b27",
"summary": "Resolution-only review in progress. Read canonical policy, contract, latest checkpoint, both open surprises, verifier report/manifest and ABI handoff. Observations: archived manifest records 8 successful objdump subprocesses but failed nested-copy-wide-row-prefix and stale session; raw review pending. Direct git checks confirm engine HEAD 7741d42fc5e4e761e6449bdaf0e4a61d00036a23 common-dir /home/alex/sots-engine/.git and RE HEAD 3bfde5a70d874a723e797a695bbd847fd82c0aa7 common-dir /home/alex/sots-re/.git in assigned /tmp/opencode/sots-final-research-{engine,re}. Launcher source_before available in campaign/runtime/runs/run-daefd1b77558f324ae730b27.json. Initial relative-path compound control command denied by resolver permissions; no execution and no bypass attempted. Binary/tool identity currently documentary from archived manifest, not freshly rehashed. Decisions: no game-mechanism interpretation or acceptance; both surprises remain blocked pending raw review and scoped decisions. No experiments, source edits, delegation, lab access or leases acquired; no cleanup required.",
"timestamp": "2026-09-10T04:49:09.790016+00:00"
}

View file

@ -0,0 +1,23 @@
{
"actor": "research-abi-correction-verifier",
"artifacts": [
{
"path": "verify/results/research-completion-abi-correction-verifier/verification-plan-run-ee78b8773688ca09f8046e21.md",
"sha256": "539210bbc8c1fdda351c7124e5a413d8432ba3e420a1b70bba830cce5ed33dc4"
},
{
"path": "verify/results/research-completion-abi/run-16f8e9b6376b278c4870be09/manifest.json",
"sha256": "4f3b4b28002a22521d2e7b87c8f82d63b21bf9f48918cc4ab6a7f629155cd101"
}
],
"basis": "aaddeb76f74bbd1a43671f882770ec84a7d690b4060d060ef1a68f918e8edbb0",
"contract": "research-completion-abi",
"id": "16467a02077d4a5b689b5531",
"model": "openai/gpt-5.6-sol",
"next_action": "Run a fresh verifier-owned four-window objdump reproduction plus +4 stop-boundary ablation, hash all outputs, and compare instruction rows and stack-write/call ordering against the predeclared falsifiers.",
"role": "verifier",
"schema": "sots-checkpoint/1",
"session": "run-ee78b8773688ca09f8046e21",
"summary": "Pre-experiment checkpoint. Observations: canonical status is verification with no open surprises; campaign validation passes. Assigned source-binding independently rehashes exactly to engine ccd8e02083e8d2e2b3e97976ace2273c8f924dfc02a39e919004eaf3544c50fd and RE 6696fd5201e144843617cbf6d78b41b5287ad5dcc9fa1e8aaa861d52b64e72e8 at the contract HEADs, matching the analyst manifest. The handoff manifest declares four nonempty zero-return GNU objdump 2.38 captures over binary SHA256 970b7de729956a53094c7eb98aba4270aee98e2fed5daf0d39e290013c90c841. Decision: verification plan now predeclares identity/execution failures, stack-write/copy/ordering/lifetime falsifiers, required static branches and distinct states, and a held-out +4 stop-boundary ablation targeting prior truncation failures. It explicitly limits success to independent static comparison, not live allocator safety, runtime execution, or replacement acceptance. Tests so far: source-binding, campaign status, and validate passed; capture not yet run. No lease/resource use or lab/source/index mutation. Blocker: none before read-only local capture; any falsifier triggers surprise and pause.",
"timestamp": "2026-09-10T04:39:38.094702+00:00"
}

View file

@ -0,0 +1,19 @@
{
"actor": "research-abi-correction-verifier",
"artifacts": [
{
"path": "verify/results/research-completion-abi/run-16f8e9b6376b278c4870be09/manifest.json",
"sha256": "4f3b4b28002a22521d2e7b87c8f82d63b21bf9f48918cc4ab6a7f629155cd101"
}
],
"basis": "aaddeb76f74bbd1a43671f882770ec84a7d690b4060d060ef1a68f918e8edbb0",
"contract": "research-completion-abi",
"id": "571f0a480c9255cc8097b5fb",
"model": "openai/gpt-5.6-sol",
"next_action": "Compute exact paired source bindings and inspect the corrected run manifest/report/raw four-window captures to define falsifiers, required branch exposures, and distinct states before reproduction.",
"role": "verifier",
"schema": "sots-checkpoint/1",
"session": "run-ee78b8773688ca09f8046e21",
"summary": "Recovery checkpoint. Observations: read canonical AGENTS.md, campaign/README.md, current policy, contract, latest lead checkpoint, and all surprise records; all surprises are resolved. Contract is verification and requests independent reproduction of corrected run-16f8e9b6376b278c4870be09. Assigned engine HEAD is 7741d42fc5e4e761e6449bdaf0e4a61d00036a23 with common-dir /home/alex/sots-engine/.git; assigned RE HEAD is 3bfde5a70d874a723e797a695bbd847fd82c0aa7 with common-dir /home/alex/sots-re/.git. Both match contract baselines and are intentionally dirty source snapshots; exact source-binding digests remain to be measured. No resource lease is held or needed; no VM, Ghidra, build-host, game, engine, allocator, Git index, or source mutation occurred. Decision: proceed only with read-only handoff inspection and local reproduction after explicitly defining falsifiers, branches, and states. Tests: identity commands passed; no evidence reproduction run yet. Blockers: none currently; any binary/tool/hash mismatch or contradictory ABI interpretation will be recorded as a surprise and affected work paused.",
"timestamp": "2026-09-10T04:36:55.123032+00:00"
}

View file

@ -0,0 +1,23 @@
{
"actor": "research-abi-correction-verifier",
"artifacts": [
{
"path": "verify/results/research-completion-abi-correction-verifier/verification-plan-run-ee78b8773688ca09f8046e21.md",
"sha256": "539210bbc8c1fdda351c7124e5a413d8432ba3e420a1b70bba830cce5ed33dc4"
},
{
"path": "verify/results/research-completion-abi/run-16f8e9b6376b278c4870be09/manifest.json",
"sha256": "4f3b4b28002a22521d2e7b87c8f82d63b21bf9f48918cc4ab6a7f629155cd101"
}
],
"basis": "aaddeb76f74bbd1a43671f882770ec84a7d690b4060d060ef1a68f918e8edbb0",
"contract": "research-completion-abi",
"id": "7608da5661fb071222d780b6",
"model": "openai/gpt-5.6-sol",
"next_action": "Run python3 verify/results/research-completion-abi-correction-verifier/reproduce_run_ee78b8773688ca09f8046e21.py from canonical RE and inspect every generated command/check plus decoded instruction ordering.",
"role": "verifier",
"schema": "sots-checkpoint/1",
"session": "run-5bd0e537bb0c4c4f43987ac1",
"summary": "Pre-experiment recovery checkpoint. Observations: read canonical AGENTS/campaign README/current policy, contract, prior checkpoint, all surprise records; status is verification, open_surprises is empty, validate passes. Assigned worktrees have contract HEADs and correct common repositories; their expected dirty/untracked manifests independently source-bind to engine ccd8e02083e8d2e2b3e97976ace2273c8f924dfc02a39e919004eaf3544c50fd and RE 6696fd5201e144843617cbf6d78b41b5287ad5dcc9fa1e8aaa861d52b64e72e8. Input hashes to 970b7de729956a53094c7eb98aba4270aee98e2fed5daf0d39e290013c90c841 at 7898624 bytes. /usr/bin/objdump is a 24-byte symlink whose dereferenced executable is 373888 bytes and hashes to 1eaaef2e7f57c4c7f69115c495e2466f5a8c8e5f3bc42221d092382f30f9d4cd; version is GNU objdump 2.38, consistent with Path.stat/read_bytes capture semantics. Decision: retain predeclared falsifiers, required static states/branches, and held-out +4 stop ablation in attached plan. Reject identity mismatch, nonzero/empty/truncated execution, archive differences, pre-call [EBP-0x20] write, copy/order/lifetime contradictions. Scope remains independent static full compare only, not original runtime, allocator safety, replacement or integrated replay. No lease or lab use; no source edits. Blocker: none before read-only capture.",
"timestamp": "2026-09-10T04:44:13.474607+00:00"
}

View file

@ -0,0 +1,31 @@
{
"actor": "sots-lead",
"artifacts": [
{
"path": "verify/results/research-completion-abi/run-16f8e9b6376b278c4870be09/manifest.json",
"sha256": "4f3b4b28002a22521d2e7b87c8f82d63b21bf9f48918cc4ab6a7f629155cd101"
},
{
"path": "verify/results/research-completion-abi/run-16f8e9b6376b278c4870be09/report.md",
"sha256": "f37e3c4bbf4c0dd249bb152422a786172d14d77fc912c7d8a4cb0d7240c0a3c7"
},
{
"path": "campaign/research/research-completion-abi.md",
"sha256": "23912a90a275f36679e1ed03d9d8830359299a2ecc269ec075f07d6f7425f4f6"
},
{
"path": "verify/results/research-completion-abi/recovered-static.md",
"sha256": "b6bfe302ebc96ab65eab31a86ff286a4bd3c43f3bba16610d9e87b04e5d40c35"
}
],
"basis": "d784af9f162cbabd289328598f71b41b78b6ffc3b78572072d04b6988ca51d5c",
"contract": "research-completion-abi",
"id": "9376a5dba4673bb414855d9c",
"model": "openai/gpt-5.6-sol",
"next_action": "Launch one fresh bounded research-completion-abi verifier quantum as actor research-abi-independent to reproduce and challenge the corrected four-window package, publish source-bound evidence and a verdict, and leave integration/acceptance to the lead.",
"role": "lead",
"schema": "sots-checkpoint/1",
"session": "lead-verifier-assignment-20260910",
"summary": "Lead assignment checkpoint. Fresh analyst correction package run-16f8e9b6376b278c4870be09 is complete and campaign validation plus 37 campaign tests pass. Contract ownership is transferred to distinct verifier research-abi-independent. No engine, VM, Ghidra, game, allocator or build-host mutation occurred. The verifier must independently reproduce all four corrected windows and challenge last-match, spare/full, empty/nonempty, cleanup-before-store, provenance and static-only limitations; no acceptance may be inferred before a bound evidence record and verdict.",
"timestamp": "2026-09-10T04:33:17.494184+00:00"
}

View file

@ -0,0 +1,39 @@
{
"actor": "research-abi-correction-verifier",
"artifacts": [
{
"path": "verify/results/research-completion-abi-correction-verifier/report-run-5bd0e537bb0c4c4f43987ac1.md",
"sha256": "c33ce30e6bb907aa4140b287afc9198bd503e9da179ff3adb8921ca3ba1b87fc"
},
{
"path": "verify/results/research-completion-abi-correction-verifier/run-ee78b8773688ca09f8046e21/manifest.json",
"sha256": "50aa35e22432b153d14dbd6a5cced3ce0ac8826c79b56f500a0ce96a32619393"
},
{
"path": "verify/results/research-completion-abi-correction-verifier/run-ee78b8773688ca09f8046e21/nested-copy-exact.stdout.txt",
"sha256": "e3988aa615066dce65ec16de0d61051ffc5deafe8c8eef4aeb0bbfbe931204a1"
},
{
"path": "verify/results/research-completion-abi-correction-verifier/run-ee78b8773688ca09f8046e21/nested-copy-wide.stdout.txt",
"sha256": "4d9a176ee3c9a8e449026e421520541000d9792a9d11cbc416318d7e26b06b5c"
},
{
"path": "campaign/runtime/surprises/s-4f4fb5e8ee42ccff7e68efb5.json",
"sha256": "8bdaf42989c5946491d63833d9fe4c2e79c3a3024b6176fdd538f0693cf1e3a8"
},
{
"path": "campaign/runtime/surprises/s-d44b9f9e62272794d88bbed6.json",
"sha256": "6b2f182b492dc484642fe2e45f60d5dd02a0deda34f841b48473c380876ada94"
}
],
"basis": "aaddeb76f74bbd1a43671f882770ec84a7d690b4060d060ef1a68f918e8edbb0",
"contract": "research-completion-abi",
"id": "bbe83c0b7516313cc7cc27b2",
"model": "openai/gpt-5.6-sol",
"next_action": "Launch an authorized openai/gpt-6-astra resolver for research-completion-abi to resolve s-4f4fb5e8ee42ccff7e68efb5 and s-d44b9f9e62272794d88bbed6 before any analyst or verifier capture resumes.",
"role": "verifier",
"schema": "sots-checkpoint/1",
"session": "run-5bd0e537bb0c4c4f43987ac1",
"summary": "Quantum stop checkpoint. Observations: source bindings and contract HEAD/common-repository identities matched the prior handoff; campaign validate passed; binary SHA256/size and dereferenced GNU objdump 2.38 SHA256/size matched. Reproduction command: python3 verify/results/research-completion-abi-correction-verifier/reproduce_run_ee78b8773688ca09f8046e21.py from canonical RE. It exited 1 after 8 objdump subprocesses. All had return 0, nonempty stdout, empty stderr; all four exact streams byte-match analyst captures. Binary/tool checks and static ABI/order markers pass, including independently enumerated zero writes to [EBP-0x20] before 0x885413. Held-out +4 ablation failed 1/45 checks: nested-copy exact stop 0x779a20 truncates instruction at 0x779a1f to byte 74; widened output gives 74 10 and exposes that exact rows are not a prefix. The widened 0x779a24 boundary itself truncates a call at 0x779a23. Failed prediction is retained as failure, not success. The inherited helper also hard-codes stale prior session run-ee78b8773688ca09f8046e21 in its newly generated manifest, so that manifest is rejected as current-session evidence; raw streams remain measurements and current report records actual invocation. Decisions: opened s-4f4fb5e8ee42ccff7e68efb5 and s-d44b9f9e62272794d88bbed6; contract is now blocked and affected verification stopped. No verdict/evidence promotion. Scope achieved only partial independent static compare, not full compare, original-assisted/live compare, independent replacement, allocator safety, whole-state/RNG validation, or integrated replay. No lease/lab operations, implementation edits, staging, commits, pushes, or resource mutation. Blockers: both open surprises require Astra resolution and fresh provenance-complete capture.",
"timestamp": "2026-09-10T04:47:11.721030+00:00"
}

View file

@ -0,0 +1,31 @@
{
"actor": "sots-lead",
"artifacts": [
{
"path": "verify/results/research-completion-abi/run-16f8e9b6376b278c4870be09/manifest.json",
"sha256": "4f3b4b28002a22521d2e7b87c8f82d63b21bf9f48918cc4ab6a7f629155cd101"
},
{
"path": "verify/results/research-completion-abi/run-16f8e9b6376b278c4870be09/report.md",
"sha256": "f37e3c4bbf4c0dd249bb152422a786172d14d77fc912c7d8a4cb0d7240c0a3c7"
},
{
"path": "campaign/research/research-completion-abi.md",
"sha256": "23912a90a275f36679e1ed03d9d8830359299a2ecc269ec075f07d6f7425f4f6"
},
{
"path": "verify/results/research-completion-abi/recovered-static.md",
"sha256": "b6bfe302ebc96ab65eab31a86ff286a4bd3c43f3bba16610d9e87b04e5d40c35"
}
],
"basis": "aaddeb76f74bbd1a43671f882770ec84a7d690b4060d060ef1a68f918e8edbb0",
"contract": "research-completion-abi",
"id": "e3bbdd77d84190f5cb086090",
"model": "openai/gpt-5.6-sol",
"next_action": "Launch one fresh bounded verifier quantum as research-abi-correction-verifier to independently reproduce and challenge the corrected four-window package, then publish source-bound evidence and a verdict without promoting the contract.",
"role": "lead",
"schema": "sots-checkpoint/1",
"session": "lead-verifier-assignment-20260910b",
"summary": "Lead verifier assignment checkpoint after restoring author ownership for independence controls. Contract is in verification; author remains research-abi-analyst and assigned distinct verifier is research-abi-correction-verifier. Fresh repair package run-16f8e9b6376b278c4870be09 and corrected handoffs are unchanged. Campaign validation and 37 campaign tests passed. No VM, engine, game, allocator, Ghidra or build-host mutation occurred.",
"timestamp": "2026-09-10T04:34:51.019450+00:00"
}

View file

@ -0,0 +1,47 @@
{
"actor": "research ABI surprise resolver",
"artifacts": [
{
"path": "campaign/runtime/decisions/d-fd5aff1eaf78a8c15d96723c.json",
"sha256": "c58922b1bb4fd2c0c4bb5106bcc72de72a6f92c4ad533f7cd0c9f711d4b44ea7"
},
{
"path": "campaign/runtime/decisions/d-0bb927e63b915c87a58d4257.json",
"sha256": "866054afc1970b3cbb231d52386313a865d1165d87df72ca0057782fa81ead10"
},
{
"path": "verify/results/research-completion-abi-correction-verifier/report-run-5bd0e537bb0c4c4f43987ac1.md",
"sha256": "c33ce30e6bb907aa4140b287afc9198bd503e9da179ff3adb8921ca3ba1b87fc"
},
{
"path": "verify/results/research-completion-abi-correction-verifier/run-ee78b8773688ca09f8046e21/manifest.json",
"sha256": "50aa35e22432b153d14dbd6a5cced3ce0ac8826c79b56f500a0ce96a32619393"
},
{
"path": "verify/results/research-completion-abi-correction-verifier/run-ee78b8773688ca09f8046e21/nested-copy-exact.stdout.txt",
"sha256": "e3988aa615066dce65ec16de0d61051ffc5deafe8c8eef4aeb0bbfbe931204a1"
},
{
"path": "verify/results/research-completion-abi-correction-verifier/run-ee78b8773688ca09f8046e21/nested-copy-wide.stdout.txt",
"sha256": "4d9a176ee3c9a8e449026e421520541000d9792a9d11cbc416318d7e26b06b5c"
},
{
"path": "verify/results/research-completion-abi-correction-verifier/reproduce_run_ee78b8773688ca09f8046e21.py",
"sha256": "28933bf5d05119e52c3d28c37a87abb38793a4b692dad96121c0e541a2fde2f7"
},
{
"path": "verify/results/research-completion-abi/run-16f8e9b6376b278c4870be09/manifest.json",
"sha256": "4f3b4b28002a22521d2e7b87c8f82d63b21bf9f48918cc4ab6a7f629155cd101"
}
],
"basis": "aaddeb76f74bbd1a43671f882770ec84a7d690b4060d060ef1a68f918e8edbb0",
"contract": "research-completion-abi",
"id": "ed14042366e407a5dc26e7a1",
"model": "openai/gpt-6-astra",
"next_action": "Lead schedules research-abi-analyst through normal lifecycle controls for a fresh static-only capture quantum implementing the probes in d-fd5aff1eaf78a8c15d96723c and d-0bb927e63b915c87a58d4257, using a new real-session output directory before independent verifier reproduction.",
"role": "resolver",
"schema": "sots-checkpoint/1",
"session": "run-daefd1b77558f324ae730b27",
"summary": "Resolution-only quantum complete. Observations: read canonical AGENTS/policy/README, ABI contract/latest checkpoint, both surprises, affected bridge/replacement contracts, prior decision d-b51f3f76803e852ed250846a, analyst and verifier manifests, helper and raw four exact plus nested-copy-wide streams. Exact stop 0x779a20 truncates 74 10; +4 stop 0x779a24 truncates later e8 call. Nested-copy body/cleanup through 0x779926 precedes affected later code. Helper hard-codes prior session/output and overwrites. Archived eight objdump executions are positive; aggregate reproduction failed, not pass. Binary 7898624 bytes SHA256 970b7de729956a53094c7eb98aba4270aee98e2fed5daf0d39e290013c90c841 and GNU objdump 2.38/373888 bytes SHA256 1eaaef2e7f57c4c7f69115c495e2466f5a8c8e5f3bc42221d092382f30f9d4cd are documentary identities, not fresh resolver rehashes. Direct git HEAD/common-dir match: /tmp/opencode/sots-final-research-engine at 7741d42fc5e4e761e6449bdaf0e4a61d00036a23, /home/alex/sots-engine/.git; /tmp/opencode/sots-final-research-re at 3bfde5a70d874a723e797a695bbd847fd82c0aa7, /home/alex/sots-re/.git. Both have preexisting dirty/untracked source, inspected status; historical source-content hashes engine ccd8e02083e8d2e2b3e97976ace2273c8f924dfc02a39e919004eaf3544c50fd / RE 6696fd5201e144843617cbf6d78b41b5287ad5dcc9fa1e8aaa861d52b64e72e8 not freshly rebound. Current launch source_before in runtime/runs/run-daefd1b77558f324ae730b27.json. Decisions: d-fd5aff1eaf78a8c15d96723c and d-0bb927e63b915c87a58d4257 close both surprises with precise survives/qualified/overturned domains, invalidation and unexecuted cheapest probes. Contract returns needs-revision, no acceptance or evidence restoration. Earlier static EvTurn correction survives; full stream and current-session acceptance do not. Require new session-specific fail-if-exists analyst capture, complete-boundary/raw-byte controls, then fresh independent integrated reproduction including archived records. Bridge remains needs-revision and replacement proposed/dependency-gated; their accepted-ABI prose is not current status. Tests: campaign validate research-completion-abi passed; no experiment/reproduction/game/build performed. Initial compound relative-path shell call denied; no bypass. No source/architecture edits, delegation, staging, commits, pushes, VM/Ghidra/build-host access or mutation. Lease directory inspected only; no resource acquired or assumed available, cleanup not applicable. Blockers: new captures, truthful provenance, independent integrated evidence; runtime allocator/full-capacity/exception/RNG/replacement claims remain unmeasured. Integrator must link actual decisions and regenerate projections only after integration; board/current pointers untouched.",
"timestamp": "2026-09-10T04:51:50.291459+00:00"
}

View file

@ -0,0 +1,14 @@
{
"actor": "research ABI surprise resolver",
"contract": "research-completion-abi",
"explanation": "Astra resolution-only decision, session run-daefd1b77558f324ae730b27; apply jointly with d-fd5aff1eaf78a8c15d96723c. OBSERVATION: inspected verify/results/research-completion-abi-correction-verifier/reproduce_run_ee78b8773688ca09f8046e21.py. Lines 7 and 72 hard-code prior output directory and session; lines 26/36/84 allow overwriting prior outputs. Actual-session report-run-5bd0e537bb0c4c4f43987ac1.md records current invocation and exit 1; generated run-ee78b8773688ca09f8046e21/manifest.json claims prior session with fresh timestamp. Current checkpoint 070383fd013a0e4b1a2ef5e0 rehashed that manifest/report to the inherited checkpoint hashes. Binary/tool/source and positive static execution qualifications are recorded in d-fd5aff1eaf78a8c15d96723c; no fresh binary execution or runtime neutrality measurement here. No basis to infer a different game build or game mechanism from stale provenance.\nOVERTURNED in exact current-session domain: manifest is truthful evidence of run-5bd0e537bb0c4c4f43987ac1, inherited helper is safely reusable unchanged across fresh sessions, and fresh timestamp/identical stdout repairs stale session identity. QUALIFIED: raw outputs and report survive as archived static measurements with documented provenance defect, not independent current-session or integrated acceptance. SURVIVES: failed boundary challenge is a failure, eight positive objdump subprocess records support static capture rather than zero-execution, and unaffected decoded ownership rows retain only the partial static domain in companion decision. A later report cannot retroactively turn overwritten prior-session output into an immutable original-run bundle.\nINVALIDATE current-session/full-compare acceptance use of the entire verifier run-ee78b8773688ca09f8046e21/manifest.json package, its hard-coded helper as a fresh-run recipe, and any checkpoint/verdict depending on that attribution. Preserve original files and failure report; no in-place relabeling, rehashing old measurements under new source, or overwriting again. Evidence array already empty; earlier invalidated integrated evidence/verdict remains invalid. No claim that all historical instruction bytes are false. Revised dependencies: a fresh uniquely named analyst package and a separately executed independent verifier package, each with explicit immutable session/actor/role/model, invocation/time, source-content bindings, original input and dereferenced tool identity, argv/cwd/streams/results and artifact hashes. Harness/interpreter identity must be bound as consumed tooling, not inferred from Git HEAD. Full instruction/dataflow review must accompany marker checks; helper regex matches only mov DWORD PTR [ebp-0x20] and alone is not exhaustive def/use proof. Both existing acceptance criteria, archived-record checking and integrated independent reproduction remain mandatory.\nVALID NEXT ACTION: lead schedules the existing analyst for static capture repair under normal lifecycle controls, using companion boundary probe and a new session-specific output directory with fail-if-exists semantics. Direct commands with a contemporaneous immutable manifest are sufficient; no general framework changes needed. Independent verifier follows in a separate execution after fresh analyst handoff. Closing these surprises permits needs-revision only, not ready/accepted; live-record-bridge and research-replacement remain dependency-gated, no implementation/lab authorization, and no projection publication until integration. This resolver makes no source edits or nested launches.",
"id": "d-0bb927e63b915c87a58d4257",
"invalidated_checkpoint": null,
"invalidated_evidence": [],
"model": "openai/gpt-6-astra",
"probe": "Cheapest provenance discriminator before capture: supply the actual new campaign run session explicitly to a fresh minimal capture recipe/direct manifest; verify it equals the launch record and output directory and that the directory does not already exist. Predeclare negative checks rejecting missing session, stale prior-session ID and reused output location before running objdump. Archive the recipe and interpreter/tool/source/input identities before capture; run all four exact/repaired complete-boundary windows plus companion negative boundary control into the new directory and record actual commands, timestamps, return codes and stream hashes. Fail closed on identity drift and any required failure; expected bad-boundary control must remain explicitly classified negative, never counted as a passing full stream. Independent verifier must reproduce with its own real session and fresh directory, not execute the inherited hard-coded helper or relabel this manifest. No probe was executed by resolver.",
"role": "resolver",
"schema": "sots-decision/1",
"surprise": "s-d44b9f9e62272794d88bbed6",
"timestamp": "2026-09-10T04:51:08.364275+00:00"
}

View file

@ -0,0 +1,14 @@
{
"actor": "research ABI surprise resolver",
"contract": "research-completion-abi",
"explanation": "Astra resolution-only decision; session run-daefd1b77558f324ae730b27. OBSERVATION/PROVENANCE: inspected analyst run-16f8e9b6376b278c4870be09/manifest.json and verifier run-ee78b8773688ca09f8046e21/manifest.json plus all four exact stdout streams and nested-copy-wide.stdout.txt under verify/results/research-completion-abi-correction-verifier/. Checkpoint 070383fd013a0e4b1a2ef5e0 rehashes verifier manifest 50aa35e22432b153d14dbd6a5cced3ce0ac8826c79b56f500a0ce96a32619393 and actual-session report c33ce30e6bb907aa4140b287afc9198bd503e9da179ff3adb8921ca3ba1b87fc. Exact nested-copy ends 0x779a1f with displayed byte 74; wide adds displacement 10 but ends 0x779a23 with only e8. Manifest records eight exit-zero, nonempty, empty-stderr objdump executions and four byte-exact analyst comparisons, but full harness exit is 1, not success. Documentary binary identity: 7898624 bytes SHA256 970b7de729956a53094c7eb98aba4270aee98e2fed5daf0d39e290013c90c841; GNU objdump 2.38, 373888 bytes SHA256 1eaaef2e7f57c4c7f69115c495e2466f5a8c8e5f3bc42221d092382f30f9d4cd. These were not freshly rehashed/rerun by resolver. Direct HEAD/common-dir checks match contract baselines in assigned paired worktrees; both trees are dirty, not assumed clean or identified solely by HEAD. Launcher records source_before; historical content bindings engine ccd8e02083e8d2e2b3e97976ace2273c8f924dfc02a39e919004eaf3544c50fd, RE 6696fd5201e144843617cbf6d78b41b5287ad5dcc9fa1e8aaa861d52b64e72e8 are documentary, not new measurements. INSTRUMENT: stop-address affects displayed instruction bytes despite a decoded target and return zero; +4 is not a completeness guarantee. No game/hook execution or runtime neutrality measurement occurred. This is capture-boundary interference, not a stale-build/game-mechanism diagnosis.\nOVERTURNED: complete four-window stream/no-truncation and nested-copy exact-row-prefix claims at stops 0x779a20/0x779a24; full independent-cross-check success and any acceptance inferred from 44/45 checks. SURVIVES as inspected static rows only: nested-copy 0x779850..0x779926 includes zero header initialization, empty/nonempty split, allocation call 0x78af40, stride 0x74, copy call 0x7725a0, EAX receiver return/ret4 and displayed cleanup calls. Truncation lies in later code, not these rows. SURVIVES under valid containers and normally returning helpers: get/create last-match scan, no pre-append initialization of EBP-0x20, append source+4 copy before nested-copy before last advance, temporary cleanup before requested-turn store, nested destructor null/non-null loop/free/three-pointer zeroing. Prior d-b51f3f76803e852ed250846a correction is not reversed. QUALIFIED: these are partial static understanding, not live empty/full-capacity execution, nonempty record validation, allocator safety, exception safety, RNG state accounting, standalone replacement or integrated acceptance. Other ABI/string/dedup/pruning claims are unaffected historical scope, not freshly recertified here.\nINVALIDATE for complete-stream/current acceptance use: analyst run-16f8e9b6376b278c4870be09/nested-copy.stdout.txt and its package completeness; verifier run-ee78b8773688ca09f8046e21 exact/wide nested-copy streams as complete windows; manifest full-compare scope and any passing interpretation in handoff/checkpoint bbe83c0b7516313cc7cc27b2. Preserve bytes, failed check and report as historical measurements. Contract evidence array is already empty; do not restore evidence/verdict invalidated by d-b51f3f76803e852ed250846a. Revised scope remains static-only correction, same acceptance criteria and controls-bootstrap dependency, fresh input/tool/source binding plus session-provenance repair required. research-live-record-bridge remains needs-revision and research-replacement proposed: their accepted-ABI prose is not current acceptance; all dependent implementation/live execution remains gated. No source/architecture/lab edits authorized. Lead must integrate only repaired independently reproduced evidence, link actual decisions and regenerate projections then, not write another board history.",
"id": "d-fd5aff1eaf78a8c15d96723c",
"invalidated_checkpoint": "campaign/runtime/checkpoints/research-completion-abi-070383fd013a0e4b1a2ef5e0.json",
"invalidated_evidence": [],
"model": "openai/gpt-6-astra",
"probe": "Cheapest discriminator for an authorized analyst after both resolutions and normal lifecycle scheduling: fresh pinned objdump -D -Mintel from 0x00779850 at stops 0x00779a20 (known-bad negative control), 0x00779a21 and 0x00779a23. Archived wide rows predict 74 10 ends at 0x779a21 and 8b cf ends at 0x779a23; these replacement stops are predictions, not measured here. Check raw PE section bytes across 0x779a1f..0x779a28 and instruction lengths, require the two aligned captures to be complete and prefix-consistent, and reject old stop as truncated despite exit zero. For narrowly scoped nested-copy authority use separately captured 0x779850..0x779930, retaining return and cleanup through 0x779926 and padding, excluding later routines; verify that terminal boundary too. Recapture all four ownership windows and boundary controls with current-session immutable manifests, all streams/argv/cwd/return codes/hashes and source binding. Audit all terminal instructions, not just prefix equality. Then an independent verifier reproduces the fresh package and held-out complete-boundary control before independent-cross-check; integrated evidence and archived-record checking remain required. No VM needed, no runtime claim; stop and escalate any new mismatch.",
"role": "resolver",
"schema": "sots-decision/1",
"surprise": "s-4f4fb5e8ee42ccff7e68efb5",
"timestamp": "2026-09-10T04:50:36.267192+00:00"
}

View file

@ -1,5 +1,5 @@
{ {
"contract": "research-completion-abi", "contract": "research-completion-abi",
"run": "run-16f8e9b6376b278c4870be09", "run": "run-daefd1b77558f324ae730b27",
"status": "complete" "status": "complete"
} }

File diff suppressed because it is too large Load diff

File diff suppressed because one or more lines are too long

File diff suppressed because it is too large Load diff

File diff suppressed because one or more lines are too long

File diff suppressed because it is too large Load diff

File diff suppressed because one or more lines are too long

View file

@ -0,0 +1,13 @@
{
"actor": "research-abi-correction-verifier",
"contract": "research-completion-abi",
"decision": "d-fd5aff1eaf78a8c15d96723c",
"id": "s-4f4fb5e8ee42ccff7e68efb5",
"model": "openai/gpt-5.6-sol",
"probe": "Astra must inspect verifier manifest verify/results/research-completion-abi-correction-verifier/run-ee78b8773688ca09f8046e21/manifest.json and the exact/wide nested-copy streams, confirm the 0x00779a1f terminal truncation under pinned GNU objdump 2.38 and binary hash, and prescribe a stop boundary after a complete instruction (including checking that any replacement boundary itself is not truncated). Then require fresh analyst capture/source-bound package and fresh independent reproduction before independent-cross-check can pass.",
"role": "verifier",
"schema": "sots-surprise/1",
"status": "resolved",
"summary": "Held-out +4 stop-boundary ablation falsified the predeclared no-truncation assumption for the corrected four-window package. All 8 objdump commands returned zero with nonempty stdout/empty stderr; all four exact captures byte-match the analyst archive; binary/tool/source identities pass; 44/45 checks pass. However nested-copy exact stop 0x00779a20 emits a truncated terminal row at 0x00779a1f as bytes 74, while widened stop 0x00779a24 emits the complete two-byte instruction 74 10 (je 0x00779a31), followed by a later call row also truncated at the widened boundary. Therefore the exact nested-copy capture is not a complete instruction stream and nested-copy-wide-row-prefix fails. Matching decoded ownership rows are measurements, not success. Pause affected independent acceptance; no live/lab/source mutation occurred.",
"timestamp": "2026-09-10T04:45:32.413275+00:00"
}

View file

@ -0,0 +1,13 @@
{
"actor": "research-abi-correction-verifier",
"contract": "research-completion-abi",
"decision": "d-0bb927e63b915c87a58d4257",
"id": "s-d44b9f9e62272794d88bbed6",
"model": "openai/gpt-5.6-sol",
"probe": "Astra must decide the provenance repair together with s-4f4fb5e8ee42ccff7e68efb5: require a newly generated current-session capture harness or direct command manifest that takes session as an explicit immutable input, then rerun all exact and complete-boundary windows. Reject the stale-session manifest rather than attaching it to a current verdict.",
"role": "verifier",
"schema": "sots-surprise/1",
"status": "resolved",
"summary": "Independent capture harness provenance is stale across fresh quanta: reproduce_run_ee78b8773688ca09f8046e21.py was inherited from the prior checkpoint and hard-codes session run-ee78b8773688ca09f8046e21. Executing it during current session run-5bd0e537bb0c4c4f43987ac1 generated fresh timestamp/raw streams but a manifest claiming the old session. The raw subprocess outputs remain measurements, but the manifest is not valid current-session evidence and must not be self-certified or relabeled after the fact. The current-session report explicitly records this defect. Affected verification is already paused by boundary surprise s-4f4fb5e8ee42ccff7e68efb5.",
"timestamp": "2026-09-10T04:46:35.617690+00:00"
}

View file

@ -0,0 +1,9 @@
{
"actor": "sots-lead",
"contract": "research-completion-abi",
"from": "implementing",
"model": "openai/gpt-5.6-sol",
"role": "lead",
"timestamp": "2026-09-10T04:33:27.064636+00:00",
"to": "verification"
}

View file

@ -0,0 +1,9 @@
{
"actor": "sots-lead",
"contract": "research-completion-abi",
"from": "ready",
"model": "openai/gpt-5.6-sol",
"role": "lead",
"timestamp": "2026-09-10T04:33:00.422019+00:00",
"to": "implementing"
}

View file

@ -0,0 +1,9 @@
{
"actor": "sots-lead",
"contract": "research-completion-abi",
"from": "needs-revision",
"model": "openai/gpt-5.6-sol",
"role": "lead",
"timestamp": "2026-09-10T04:32:53.781271+00:00",
"to": "ready"
}

View file

@ -2,7 +2,7 @@
"actor": "research-abi-independent", "actor": "research-abi-independent",
"basis": "aaddeb76f74bbd1a43671f882770ec84a7d690b4060d060ef1a68f918e8edbb0", "basis": "aaddeb76f74bbd1a43671f882770ec84a7d690b4060d060ef1a68f918e8edbb0",
"contract": "research-completion-abi", "contract": "research-completion-abi",
"decision": "d-b51f3f76803e852ed250846a", "decision": "d-0bb927e63b915c87a58d4257",
"evidence_digest": "e5073be0f1187ee65c203eb9ad20adc64d18ff2d3314d554f58bd8487dafa931", "evidence_digest": "e5073be0f1187ee65c203eb9ad20adc64d18ff2d3314d554f58bd8487dafa931",
"explanation": "Scoped integrated PASS over the current two-record integrated evidence array. Fresh handoff reproduction executed 22 nonempty static windows plus strict archived save parse/checksum: 24 positive subprocesses, empty stderr, no skips; manifest matches the integrated artifact except session and state is byte-identical. Seven narrow/wide boundaries reproduce complete ret 4/ret 8 bytes. Held-out direct-PE ablation confirmed each exact return and rejected all minus-one/plus-one shifted starts; static inspection exposed distinct 0x2c/0x74 strides, deep-copy calls, three guarded long-string deletes, description inequality and three unordered-or-unequal float branches. Actual state inspection found EvNxID 4, turn-3 count 2, event ID 3 fields/defaults, exact 609080-byte rebuild, and a 2503-byte RNG leaf with digest 0978fdf34ff7962f76c2de810dc93e0a. Integrated source/input/binary/outcome hashes remain bound and campaign tests/validation pass. Scope is independent static reproduction plus one archived state only: no live allocator safety, original differential, replacement or replay acceptance; runtime branch residuals remain. Historical failed provenance/description predictions remain failures resolved by Astra.", "explanation": "Scoped integrated PASS over the current two-record integrated evidence array. Fresh handoff reproduction executed 22 nonempty static windows plus strict archived save parse/checksum: 24 positive subprocesses, empty stderr, no skips; manifest matches the integrated artifact except session and state is byte-identical. Seven narrow/wide boundaries reproduce complete ret 4/ret 8 bytes. Held-out direct-PE ablation confirmed each exact return and rejected all minus-one/plus-one shifted starts; static inspection exposed distinct 0x2c/0x74 strides, deep-copy calls, three guarded long-string deletes, description inequality and three unordered-or-unequal float branches. Actual state inspection found EvNxID 4, turn-3 count 2, event ID 3 fields/defaults, exact 609080-byte rebuild, and a 2503-byte RNG leaf with digest 0978fdf34ff7962f76c2de810dc93e0a. Integrated source/input/binary/outcome hashes remain bound and campaign tests/validation pass. Scope is independent static reproduction plus one archived state only: no live allocator safety, original differential, replacement or replay acceptance; runtime branch residuals remain. Historical failed provenance/description predictions remain failures resolved by Astra.",
"model": "openai/gpt-5.6-sol", "model": "openai/gpt-5.6-sol",

View file

@ -0,0 +1,63 @@
# Independent correction verification result
Actor `research-abi-correction-verifier`, role `verifier`, requested model
`openai/gpt-5.6-sol`, campaign session `run-5bd0e537bb0c4c4f43987ac1`.
## Scope and identities
This was an independent static partial comparison plus held-out stop-boundary ablation. It was not
original-game runtime comparison, live allocator validation, independent replacement, integrated
replay, or an acceptance verdict. The paired source bindings reproduced as engine
`ccd8e02083e8d2e2b3e97976ace2273c8f924dfc02a39e919004eaf3544c50fd` and RE
`6696fd5201e144843617cbf6d78b41b5287ad5dcc9fa1e8aaa861d52b64e72e8` at the contract HEADs.
The 7,898,624-byte input SHA-256 was
`970b7de729956a53094c7eb98aba4270aee98e2fed5daf0d39e290013c90c841`. The dereferenced
373,888-byte GNU objdump 2.38 executable SHA-256 was
`1eaaef2e7f57c4c7f69115c495e2466f5a8c8e5f3bc42221d092382f30f9d4cd`.
## Reproduction and observations
From `/home/alex/sots-re`:
```sh
python3 verify/results/research-completion-abi-correction-verifier/reproduce_run_ee78b8773688ca09f8046e21.py
```
The process exited 1 after eight positive objdump executions (four exact windows and four held-out
windows widened by four bytes). Every subprocess returned zero, emitted nonempty stdout, and emitted
empty stderr. All four exact stdout streams byte-matched the analyst captures. Binary/tool checks,
the independent empty list of pre-`0x00885413` writes to `[EBP-0x20]`, get/create ordering, append
copy ordering, nested empty/nonempty-copy branch markers, and destructor null/non-null branch markers
passed. The generated manifest reports 44 passing checks and one failure.
The failed check is `nested-copy-wide-row-prefix`. Exact stop `0x00779a20` ends with:
```text
779a1f: 74 je 0x779a31
```
The widened stop `0x00779a24` exposes the complete instruction:
```text
779a1f: 74 10 je 0x779a31
```
and then rows at `0x00779a21` and `0x00779a23`; the latter call is itself truncated by that widened
boundary. Thus exact rows are not a byte-identical prefix of widened rows and the analyst's
`nested-copy` window has a truncated terminal instruction. This falsifies the predeclared boundary
prediction. Surprise `s-4f4fb5e8ee42ccff7e68efb5` records and blocks the affected interpretation.
## Provenance defect and residuals
The reproduction helper was inherited from the prior verifier checkpoint and hard-codes prior
session `run-ee78b8773688ca09f8046e21` into its generated manifest. Although the raw commands ran in
this fresh quantum, that manifest does not truthfully identify the current campaign session and is
not acceptable as a current-session evidence record. This report records the actual invocation and
does not relabel the generated manifest.
No success is claimed for the failed full compare. Surviving rows remain partial static
measurements. Residuals include a complete non-truncated nested-copy boundary, fresh analyst and
verifier provenance, live spare/full-capacity fixtures, nonempty live nested-copy state, allocator
safety, induced unwind, original runtime comparison, whole-state/RNG validation, independent
replacement, and integrated replay. No RNG execution occurred; static no-RNG prose was not treated
as runtime state accounting.

View file

@ -0,0 +1,87 @@
#!/usr/bin/env python3
import hashlib, json, re, subprocess
from datetime import datetime, timezone
from pathlib import Path
ROOT = Path('/home/alex/sots-re')
OUT = ROOT / 'verify/results/research-completion-abi-correction-verifier/run-ee78b8773688ca09f8046e21'
AUTHOR = ROOT / 'verify/results/research-completion-abi/run-16f8e9b6376b278c4870be09'
TOOL = Path('/usr/bin/objdump')
BINARY = ROOT / 'dumps/sots.exe'
WINDOWS = {
'turn-get-create': (0x00885380, 0x0088544a),
'turn-append': (0x00884cb0, 0x00884d8f),
'nested-copy': (0x00779850, 0x00779a20),
'nested-dtor': (0x00629580, 0x006295ca),
}
EXPECTED = {
'binary': '970b7de729956a53094c7eb98aba4270aee98e2fed5daf0d39e290013c90c841',
'tool': '1eaaef2e7f57c4c7f69115c495e2466f5a8c8e5f3bc42221d092382f30f9d4cd',
}
ROW = re.compile(rb'^\s*[0-9a-f]+:\s', re.M)
def sha(data): return hashlib.sha256(data).hexdigest()
def rows(data): return [line for line in data.splitlines() if ROW.match(line)]
OUT.mkdir(parents=True, exist_ok=True)
checks = []
records = []
for name, (start, stop) in WINDOWS.items():
variants = {}
for suffix, end in (('exact', stop), ('wide', stop + 4)):
argv = [str(TOOL), '-D', '-Mintel', f'--start-address=0x{start:08x}',
f'--stop-address=0x{end:08x}', str(BINARY)]
p = subprocess.run(argv, cwd=ROOT, capture_output=True, check=False)
for stream, data in (('stdout', p.stdout), ('stderr', p.stderr)):
(OUT / f'{name}-{suffix}.{stream}.txt').write_bytes(data)
variants[suffix] = p.stdout
records.append({'name': name, 'variant': suffix, 'argv': argv,
'returncode': p.returncode,
'stdout': {'bytes': len(p.stdout), 'sha256': sha(p.stdout)},
'stderr': {'bytes': len(p.stderr), 'sha256': sha(p.stderr)}})
checks += [(f'{name}-{suffix}-return-zero', p.returncode == 0),
(f'{name}-{suffix}-stdout-nonempty', bool(p.stdout)),
(f'{name}-{suffix}-stderr-empty', not p.stderr)]
archived = (AUTHOR / f'{name}.stdout.txt').read_bytes()
exact_rows, wide_rows = rows(variants['exact']), rows(variants['wide'])
checks += [(f'{name}-byte-exact-author-compare', variants['exact'] == archived),
(f'{name}-wide-row-prefix', exact_rows == wide_rows[:len(exact_rows)]),
(f'{name}-wide-adds-row', len(wide_rows) > len(exact_rows))]
get = (OUT / 'turn-get-create-exact.stdout.txt').read_text()
pre_call = get.split('885413:', 1)[0]
stack20_writes = [line.strip() for line in pre_call.splitlines()
if '[ebp-0x20]' in line.lower() and re.search(r'\bmov\s+DWORD PTR \[ebp-0x20\]', line, re.I)]
append = (OUT / 'turn-append-exact.stdout.txt').read_text()
copy = (OUT / 'nested-copy-exact.stdout.txt').read_text()
dtor = (OUT / 'nested-dtor-exact.stdout.txt').read_text()
checks += [
('binary-hash', sha(BINARY.read_bytes()) == EXPECTED['binary']),
('tool-hash', sha(TOOL.read_bytes()) == EXPECTED['tool']),
('get-no-precall-ebp-minus-20-write', not stack20_writes),
('get-last-match-overwrite-visible', all(x in get for x in ('8853d3:', '8853d8:', '8853de:', '8853e6:'))),
('get-cleanup-before-final-store', get.index('885422:') < get.index('88542d:') < get.index('885433:')),
('append-source4-copy-before-nested-copy-before-advance', append.index('884d62:') < append.index('884d6c:') < append.index('884d73:') < append.index('884d78:')),
('nested-copy-three-null-initializers', all(x in copy for x in ('779885:', '779887:', '77988a:'))),
('nested-copy-empty-and-nonempty-branches', all(x in copy for x in ('7798b2:', '7798cb:', '7798d0:', '7798ed:'))),
('nested-dtor-null-branch-loop-free-zero', all(x in dtor for x in ('629586:', '6295a8:', '6295aa:', '6295b4:', '6295c0:', '6295c2:', '6295c5:'))),
]
failed = [name for name, ok in checks if not ok]
manifest = {
'schema': 'sots-abi-independent-static/1', 'session': 'run-ee78b8773688ca09f8046e21',
'actor': 'research-abi-correction-verifier', 'role': 'verifier',
'model': 'openai/gpt-5.6-sol', 'timestamp': datetime.now(timezone.utc).isoformat(),
'input': {'path': 'dumps/sots.exe', 'bytes': BINARY.stat().st_size, 'sha256': sha(BINARY.read_bytes())},
'tool': {'path': str(TOOL), 'bytes': TOOL.stat().st_size, 'sha256': sha(TOOL.read_bytes()),
'version': subprocess.run([str(TOOL), '--version'], capture_output=True, text=True, check=True).stdout.splitlines()[0]},
'author_manifest_sha256': sha((AUTHOR / 'manifest.json').read_bytes()),
'stack_writes_to_ebp_minus_20_before_0x885413': stack20_writes,
'commands': records, 'checks': [{'name': n, 'status': 'pass' if ok else 'fail'} for n, ok in checks],
'failed': failed,
'scope': 'Independent static full compare plus widened-stop boundary ablation; no live game/allocator execution or replacement acceptance.'
}
(OUT / 'manifest.json').write_text(json.dumps(manifest, indent=2) + '\n')
print(json.dumps({'commands': len(records), 'checks': len(checks), 'failed': failed,
'manifest': str((OUT / 'manifest.json').relative_to(ROOT))}, indent=2))
raise SystemExit(bool(failed))

View file

@ -0,0 +1,377 @@
{
"schema": "sots-abi-independent-static/1",
"session": "run-ee78b8773688ca09f8046e21",
"actor": "research-abi-correction-verifier",
"role": "verifier",
"model": "openai/gpt-5.6-sol",
"timestamp": "2026-09-10T04:44:36.333584+00:00",
"input": {
"path": "dumps/sots.exe",
"bytes": 7898624,
"sha256": "970b7de729956a53094c7eb98aba4270aee98e2fed5daf0d39e290013c90c841"
},
"tool": {
"path": "/usr/bin/objdump",
"bytes": 373888,
"sha256": "1eaaef2e7f57c4c7f69115c495e2466f5a8c8e5f3bc42221d092382f30f9d4cd",
"version": "GNU objdump (GNU Binutils for Ubuntu) 2.38"
},
"author_manifest_sha256": "4f3b4b28002a22521d2e7b87c8f82d63b21bf9f48918cc4ab6a7f629155cd101",
"stack_writes_to_ebp_minus_20_before_0x885413": [],
"commands": [
{
"name": "turn-get-create",
"variant": "exact",
"argv": [
"/usr/bin/objdump",
"-D",
"-Mintel",
"--start-address=0x00885380",
"--stop-address=0x0088544a",
"/home/alex/sots-re/dumps/sots.exe"
],
"returncode": 0,
"stdout": {
"bytes": 3974,
"sha256": "f6e72ba9b08fdf48d70f39379b2fb30a5adbe796072485f70c5795c10ab45ca3"
},
"stderr": {
"bytes": 0,
"sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
}
},
{
"name": "turn-get-create",
"variant": "wide",
"argv": [
"/usr/bin/objdump",
"-D",
"-Mintel",
"--start-address=0x00885380",
"--stop-address=0x0088544e",
"/home/alex/sots-re/dumps/sots.exe"
],
"returncode": 0,
"stdout": {
"bytes": 4134,
"sha256": "9cb7d2ccfcc645b3b642e520ba51c85330c57d6d4395ed3fbd4a4a1950436e80"
},
"stderr": {
"bytes": 0,
"sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
}
},
{
"name": "turn-append",
"variant": "exact",
"argv": [
"/usr/bin/objdump",
"-D",
"-Mintel",
"--start-address=0x00884cb0",
"--stop-address=0x00884d8f",
"/home/alex/sots-re/dumps/sots.exe"
],
"returncode": 0,
"stdout": {
"bytes": 4179,
"sha256": "57d6655feed0fc137bb2b7eee4bfcb09536b5a715603c917ee142770f1d52a15"
},
"stderr": {
"bytes": 0,
"sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
}
},
{
"name": "turn-append",
"variant": "wide",
"argv": [
"/usr/bin/objdump",
"-D",
"-Mintel",
"--start-address=0x00884cb0",
"--stop-address=0x00884d93",
"/home/alex/sots-re/dumps/sots.exe"
],
"returncode": 0,
"stdout": {
"bytes": 4309,
"sha256": "957339f40b2af8947cb883cc1d3a9d1e151bf7663305415065472ef9171dc33d"
},
"stderr": {
"bytes": 0,
"sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
}
},
{
"name": "nested-copy",
"variant": "exact",
"argv": [
"/usr/bin/objdump",
"-D",
"-Mintel",
"--start-address=0x00779850",
"--stop-address=0x00779a20",
"/home/alex/sots-re/dumps/sots.exe"
],
"returncode": 0,
"stdout": {
"bytes": 8469,
"sha256": "e3988aa615066dce65ec16de0d61051ffc5deafe8c8eef4aeb0bbfbe931204a1"
},
"stderr": {
"bytes": 0,
"sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
}
},
{
"name": "nested-copy",
"variant": "wide",
"argv": [
"/usr/bin/objdump",
"-D",
"-Mintel",
"--start-address=0x00779850",
"--stop-address=0x00779a24",
"/home/alex/sots-re/dumps/sots.exe"
],
"returncode": 0,
"stdout": {
"bytes": 8558,
"sha256": "4d9a176ee3c9a8e449026e421520541000d9792a9d11cbc416318d7e26b06b5c"
},
"stderr": {
"bytes": 0,
"sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
}
},
{
"name": "nested-dtor",
"variant": "exact",
"argv": [
"/usr/bin/objdump",
"-D",
"-Mintel",
"--start-address=0x00629580",
"--stop-address=0x006295ca",
"/home/alex/sots-re/dumps/sots.exe"
],
"returncode": 0,
"stdout": {
"bytes": 1727,
"sha256": "3c38887e60d009ab904772b13be93ac1eedd9bee85024e37110160a625db3a83"
},
"stderr": {
"bytes": 0,
"sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
}
},
{
"name": "nested-dtor",
"variant": "wide",
"argv": [
"/usr/bin/objdump",
"-D",
"-Mintel",
"--start-address=0x00629580",
"--stop-address=0x006295ce",
"/home/alex/sots-re/dumps/sots.exe"
],
"returncode": 0,
"stdout": {
"bytes": 1887,
"sha256": "0aba6fc800760e3a113c07238cfb6e721623eb0bb8a933a990d3e2e82823d00f"
},
"stderr": {
"bytes": 0,
"sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
}
}
],
"checks": [
{
"name": "turn-get-create-exact-return-zero",
"status": "pass"
},
{
"name": "turn-get-create-exact-stdout-nonempty",
"status": "pass"
},
{
"name": "turn-get-create-exact-stderr-empty",
"status": "pass"
},
{
"name": "turn-get-create-wide-return-zero",
"status": "pass"
},
{
"name": "turn-get-create-wide-stdout-nonempty",
"status": "pass"
},
{
"name": "turn-get-create-wide-stderr-empty",
"status": "pass"
},
{
"name": "turn-get-create-byte-exact-author-compare",
"status": "pass"
},
{
"name": "turn-get-create-wide-row-prefix",
"status": "pass"
},
{
"name": "turn-get-create-wide-adds-row",
"status": "pass"
},
{
"name": "turn-append-exact-return-zero",
"status": "pass"
},
{
"name": "turn-append-exact-stdout-nonempty",
"status": "pass"
},
{
"name": "turn-append-exact-stderr-empty",
"status": "pass"
},
{
"name": "turn-append-wide-return-zero",
"status": "pass"
},
{
"name": "turn-append-wide-stdout-nonempty",
"status": "pass"
},
{
"name": "turn-append-wide-stderr-empty",
"status": "pass"
},
{
"name": "turn-append-byte-exact-author-compare",
"status": "pass"
},
{
"name": "turn-append-wide-row-prefix",
"status": "pass"
},
{
"name": "turn-append-wide-adds-row",
"status": "pass"
},
{
"name": "nested-copy-exact-return-zero",
"status": "pass"
},
{
"name": "nested-copy-exact-stdout-nonempty",
"status": "pass"
},
{
"name": "nested-copy-exact-stderr-empty",
"status": "pass"
},
{
"name": "nested-copy-wide-return-zero",
"status": "pass"
},
{
"name": "nested-copy-wide-stdout-nonempty",
"status": "pass"
},
{
"name": "nested-copy-wide-stderr-empty",
"status": "pass"
},
{
"name": "nested-copy-byte-exact-author-compare",
"status": "pass"
},
{
"name": "nested-copy-wide-row-prefix",
"status": "fail"
},
{
"name": "nested-copy-wide-adds-row",
"status": "pass"
},
{
"name": "nested-dtor-exact-return-zero",
"status": "pass"
},
{
"name": "nested-dtor-exact-stdout-nonempty",
"status": "pass"
},
{
"name": "nested-dtor-exact-stderr-empty",
"status": "pass"
},
{
"name": "nested-dtor-wide-return-zero",
"status": "pass"
},
{
"name": "nested-dtor-wide-stdout-nonempty",
"status": "pass"
},
{
"name": "nested-dtor-wide-stderr-empty",
"status": "pass"
},
{
"name": "nested-dtor-byte-exact-author-compare",
"status": "pass"
},
{
"name": "nested-dtor-wide-row-prefix",
"status": "pass"
},
{
"name": "nested-dtor-wide-adds-row",
"status": "pass"
},
{
"name": "binary-hash",
"status": "pass"
},
{
"name": "tool-hash",
"status": "pass"
},
{
"name": "get-no-precall-ebp-minus-20-write",
"status": "pass"
},
{
"name": "get-last-match-overwrite-visible",
"status": "pass"
},
{
"name": "get-cleanup-before-final-store",
"status": "pass"
},
{
"name": "append-source4-copy-before-nested-copy-before-advance",
"status": "pass"
},
{
"name": "nested-copy-three-null-initializers",
"status": "pass"
},
{
"name": "nested-copy-empty-and-nonempty-branches",
"status": "pass"
},
{
"name": "nested-dtor-null-branch-loop-free-zero",
"status": "pass"
}
],
"failed": [
"nested-copy-wide-row-prefix"
],
"scope": "Independent static full compare plus widened-stop boundary ablation; no live game/allocator execution or replacement acceptance."
}

View file

@ -0,0 +1,175 @@
/home/alex/sots-re/dumps/sots.exe: file format pei-i386
Disassembly of section .text:
00779850 <.text+0x378850>:
779850: 55 push ebp
779851: 8b ec mov ebp,esp
779853: 6a ff push 0xffffffff
779855: 68 10 7b 98 00 push 0x987b10
77985a: 64 a1 00 00 00 00 mov eax,fs:0x0
779860: 50 push eax
779861: 83 ec 08 sub esp,0x8
779864: 53 push ebx
779865: 56 push esi
779866: 57 push edi
779867: a1 78 8b af 00 mov eax,ds:0xaf8b78
77986c: 33 c5 xor eax,ebp
77986e: 50 push eax
77986f: 8d 45 f4 lea eax,[ebp-0xc]
779872: 64 a3 00 00 00 00 mov fs:0x0,eax
779878: 89 65 f0 mov DWORD PTR [ebp-0x10],esp
77987b: 8b f1 mov esi,ecx
77987d: 89 75 ec mov DWORD PTR [ebp-0x14],esi
779880: 8b 5d 08 mov ebx,DWORD PTR [ebp+0x8]
779883: 33 c0 xor eax,eax
779885: 89 06 mov DWORD PTR [esi],eax
779887: 89 46 04 mov DWORD PTR [esi+0x4],eax
77988a: 89 46 08 mov DWORD PTR [esi+0x8],eax
77988d: 8b 4b 04 mov ecx,DWORD PTR [ebx+0x4]
779890: 2b 0b sub ecx,DWORD PTR [ebx]
779892: b8 09 cb 3d 8d mov eax,0x8d3dcb09
779897: f7 e9 imul ecx
779899: 03 d1 add edx,ecx
77989b: c1 fa 06 sar edx,0x6
77989e: 8b fa mov edi,edx
7798a0: b8 00 00 00 00 mov eax,0x0
7798a5: c1 ef 1f shr edi,0x1f
7798a8: 03 fa add edi,edx
7798aa: 89 06 mov DWORD PTR [esi],eax
7798ac: 89 46 04 mov DWORD PTR [esi+0x4],eax
7798af: 89 46 08 mov DWORD PTR [esi+0x8],eax
7798b2: 74 4b je 0x7798ff
7798b4: 81 ff 2c f7 34 02 cmp edi,0x234f72c
7798ba: 76 0b jbe 0x7798c7
7798bc: 68 90 1f 9e 00 push 0x9e1f90
7798c1: ff 15 50 d1 9d 00 call DWORD PTR ds:0x9dd150
7798c7: 8d 4e 0c lea ecx,[esi+0xc]
7798ca: 57 push edi
7798cb: e8 70 16 01 00 call 0x78af40
7798d0: 6b ff 74 imul edi,edi,0x74
7798d3: 8b 55 08 mov edx,DWORD PTR [ebp+0x8]
7798d6: 52 push edx
7798d7: 8d 56 0c lea edx,[esi+0xc]
7798da: 52 push edx
7798db: 03 f8 add edi,eax
7798dd: 89 06 mov DWORD PTR [esi],eax
7798df: 89 46 04 mov DWORD PTR [esi+0x4],eax
7798e2: 89 7e 08 mov DWORD PTR [esi+0x8],edi
7798e5: 8b 4b 04 mov ecx,DWORD PTR [ebx+0x4]
7798e8: 8b 1b mov ebx,DWORD PTR [ebx]
7798ea: 50 push eax
7798eb: 51 push ecx
7798ec: 53 push ebx
7798ed: c7 45 fc 00 00 00 00 mov DWORD PTR [ebp-0x4],0x0
7798f4: e8 a7 8c ff ff call 0x7725a0
7798f9: 83 c4 14 add esp,0x14
7798fc: 89 46 04 mov DWORD PTR [esi+0x4],eax
7798ff: 8b c6 mov eax,esi
779901: 8b 4d f4 mov ecx,DWORD PTR [ebp-0xc]
779904: 64 89 0d 00 00 00 00 mov DWORD PTR fs:0x0,ecx
77990b: 59 pop ecx
77990c: 5f pop edi
77990d: 5e pop esi
77990e: 5b pop ebx
77990f: 8b e5 mov esp,ebp
779911: 5d pop ebp
779912: c2 04 00 ret 0x4
779915: 8b 4d ec mov ecx,DWORD PTR [ebp-0x14]
779918: e8 63 fc ea ff call 0x629580
77991d: 6a 00 push 0x0
77991f: 6a 00 push 0x0
779921: e8 96 b6 1a 00 call 0x924fbc
779926: cc int3
779927: cc int3
779928: cc int3
779929: cc int3
77992a: cc int3
77992b: cc int3
77992c: cc int3
77992d: cc int3
77992e: cc int3
77992f: cc int3
779930: 55 push ebp
779931: 8b ec mov ebp,esp
779933: 6a ff push 0xffffffff
779935: 68 38 06 97 00 push 0x970638
77993a: 64 a1 00 00 00 00 mov eax,fs:0x0
779940: 50 push eax
779941: 83 ec 20 sub esp,0x20
779944: a1 78 8b af 00 mov eax,ds:0xaf8b78
779949: 33 c5 xor eax,ebp
77994b: 89 45 f0 mov DWORD PTR [ebp-0x10],eax
77994e: 56 push esi
77994f: 50 push eax
779950: 8d 45 f4 lea eax,[ebp-0xc]
779953: 64 a3 00 00 00 00 mov fs:0x0,eax
779959: 8b f1 mov esi,ecx
77995b: 8b 86 8c 00 00 00 mov eax,DWORD PTR [esi+0x8c]
779961: 85 c0 test eax,eax
779963: 75 0c jne 0x779971
779965: 68 34 24 a2 00 push 0xa22434
77996a: e8 e1 05 14 00 call 0x8b9f50
77996f: eb 7e jmp 0x7799ef
779971: 50 push eax
779972: e8 09 cc c9 ff call 0x416580
779977: 83 c4 04 add esp,0x4
77997a: 85 c0 test eax,eax
77997c: 74 0c je 0x77998a
77997e: 68 f8 23 a2 00 push 0xa223f8
779983: e8 58 08 14 00 call 0x8ba1e0
779988: eb 65 jmp 0x7799ef
77998a: e8 d1 58 dc ff call 0x53f260
77998f: c7 45 e8 0f 00 00 00 mov DWORD PTR [ebp-0x18],0xf
779996: c7 45 e4 00 00 00 00 mov DWORD PTR [ebp-0x1c],0x0
77999d: c6 45 d4 00 mov BYTE PTR [ebp-0x2c],0x0
7799a1: 8d 4d d4 lea ecx,[ebp-0x2c]
7799a4: 51 push ecx
7799a5: 50 push eax
7799a6: c7 45 fc 00 00 00 00 mov DWORD PTR [ebp-0x4],0x0
7799ad: e8 fe 52 dc ff call 0x53ecb0
7799b2: 8b 45 d4 mov eax,DWORD PTR [ebp-0x2c]
7799b5: 83 c4 08 add esp,0x8
7799b8: 83 7d e8 10 cmp DWORD PTR [ebp-0x18],0x10
7799bc: 73 03 jae 0x7799c1
7799be: 8d 45 d4 lea eax,[ebp-0x2c]
7799c1: 8b 96 8c 00 00 00 mov edx,DWORD PTR [esi+0x8c]
7799c7: 6a 00 push 0x0
7799c9: 56 push esi
7799ca: 68 a0 8d 77 00 push 0x778da0
7799cf: 68 e0 ea 76 00 push 0x76eae0
7799d4: 6a 00 push 0x0
7799d6: 50 push eax
7799d7: 52 push edx
7799d8: e8 f3 d7 c9 ff call 0x4171d0
7799dd: 83 c4 1c add esp,0x1c
7799e0: 83 7d e8 10 cmp DWORD PTR [ebp-0x18],0x10
7799e4: 72 0c jb 0x7799f2
7799e6: 8b 45 d4 mov eax,DWORD PTR [ebp-0x2c]
7799e9: 50 push eax
7799ea: e8 bb b5 1a 00 call 0x924faa
7799ef: 83 c4 04 add esp,0x4
7799f2: 8b 4d f4 mov ecx,DWORD PTR [ebp-0xc]
7799f5: 64 89 0d 00 00 00 00 mov DWORD PTR fs:0x0,ecx
7799fc: 59 pop ecx
7799fd: 5e pop esi
7799fe: 8b 4d f0 mov ecx,DWORD PTR [ebp-0x10]
779a01: 33 cd xor ecx,ebp
779a03: e8 7a b3 1a 00 call 0x924d82
779a08: 8b e5 mov esp,ebp
779a0a: 5d pop ebp
779a0b: c3 ret
779a0c: cc int3
779a0d: cc int3
779a0e: cc int3
779a0f: cc int3
779a10: 53 push ebx
779a11: 56 push esi
779a12: 8b f1 mov esi,ecx
779a14: 57 push edi
779a15: 8b be 24 01 00 00 mov edi,DWORD PTR [esi+0x124]
779a1b: 33 db xor ebx,ebx
779a1d: 3b fb cmp edi,ebx
779a1f: 74 je 0x779a31

View file

@ -0,0 +1,177 @@
/home/alex/sots-re/dumps/sots.exe: file format pei-i386
Disassembly of section .text:
00779850 <.text+0x378850>:
779850: 55 push ebp
779851: 8b ec mov ebp,esp
779853: 6a ff push 0xffffffff
779855: 68 10 7b 98 00 push 0x987b10
77985a: 64 a1 00 00 00 00 mov eax,fs:0x0
779860: 50 push eax
779861: 83 ec 08 sub esp,0x8
779864: 53 push ebx
779865: 56 push esi
779866: 57 push edi
779867: a1 78 8b af 00 mov eax,ds:0xaf8b78
77986c: 33 c5 xor eax,ebp
77986e: 50 push eax
77986f: 8d 45 f4 lea eax,[ebp-0xc]
779872: 64 a3 00 00 00 00 mov fs:0x0,eax
779878: 89 65 f0 mov DWORD PTR [ebp-0x10],esp
77987b: 8b f1 mov esi,ecx
77987d: 89 75 ec mov DWORD PTR [ebp-0x14],esi
779880: 8b 5d 08 mov ebx,DWORD PTR [ebp+0x8]
779883: 33 c0 xor eax,eax
779885: 89 06 mov DWORD PTR [esi],eax
779887: 89 46 04 mov DWORD PTR [esi+0x4],eax
77988a: 89 46 08 mov DWORD PTR [esi+0x8],eax
77988d: 8b 4b 04 mov ecx,DWORD PTR [ebx+0x4]
779890: 2b 0b sub ecx,DWORD PTR [ebx]
779892: b8 09 cb 3d 8d mov eax,0x8d3dcb09
779897: f7 e9 imul ecx
779899: 03 d1 add edx,ecx
77989b: c1 fa 06 sar edx,0x6
77989e: 8b fa mov edi,edx
7798a0: b8 00 00 00 00 mov eax,0x0
7798a5: c1 ef 1f shr edi,0x1f
7798a8: 03 fa add edi,edx
7798aa: 89 06 mov DWORD PTR [esi],eax
7798ac: 89 46 04 mov DWORD PTR [esi+0x4],eax
7798af: 89 46 08 mov DWORD PTR [esi+0x8],eax
7798b2: 74 4b je 0x7798ff
7798b4: 81 ff 2c f7 34 02 cmp edi,0x234f72c
7798ba: 76 0b jbe 0x7798c7
7798bc: 68 90 1f 9e 00 push 0x9e1f90
7798c1: ff 15 50 d1 9d 00 call DWORD PTR ds:0x9dd150
7798c7: 8d 4e 0c lea ecx,[esi+0xc]
7798ca: 57 push edi
7798cb: e8 70 16 01 00 call 0x78af40
7798d0: 6b ff 74 imul edi,edi,0x74
7798d3: 8b 55 08 mov edx,DWORD PTR [ebp+0x8]
7798d6: 52 push edx
7798d7: 8d 56 0c lea edx,[esi+0xc]
7798da: 52 push edx
7798db: 03 f8 add edi,eax
7798dd: 89 06 mov DWORD PTR [esi],eax
7798df: 89 46 04 mov DWORD PTR [esi+0x4],eax
7798e2: 89 7e 08 mov DWORD PTR [esi+0x8],edi
7798e5: 8b 4b 04 mov ecx,DWORD PTR [ebx+0x4]
7798e8: 8b 1b mov ebx,DWORD PTR [ebx]
7798ea: 50 push eax
7798eb: 51 push ecx
7798ec: 53 push ebx
7798ed: c7 45 fc 00 00 00 00 mov DWORD PTR [ebp-0x4],0x0
7798f4: e8 a7 8c ff ff call 0x7725a0
7798f9: 83 c4 14 add esp,0x14
7798fc: 89 46 04 mov DWORD PTR [esi+0x4],eax
7798ff: 8b c6 mov eax,esi
779901: 8b 4d f4 mov ecx,DWORD PTR [ebp-0xc]
779904: 64 89 0d 00 00 00 00 mov DWORD PTR fs:0x0,ecx
77990b: 59 pop ecx
77990c: 5f pop edi
77990d: 5e pop esi
77990e: 5b pop ebx
77990f: 8b e5 mov esp,ebp
779911: 5d pop ebp
779912: c2 04 00 ret 0x4
779915: 8b 4d ec mov ecx,DWORD PTR [ebp-0x14]
779918: e8 63 fc ea ff call 0x629580
77991d: 6a 00 push 0x0
77991f: 6a 00 push 0x0
779921: e8 96 b6 1a 00 call 0x924fbc
779926: cc int3
779927: cc int3
779928: cc int3
779929: cc int3
77992a: cc int3
77992b: cc int3
77992c: cc int3
77992d: cc int3
77992e: cc int3
77992f: cc int3
779930: 55 push ebp
779931: 8b ec mov ebp,esp
779933: 6a ff push 0xffffffff
779935: 68 38 06 97 00 push 0x970638
77993a: 64 a1 00 00 00 00 mov eax,fs:0x0
779940: 50 push eax
779941: 83 ec 20 sub esp,0x20
779944: a1 78 8b af 00 mov eax,ds:0xaf8b78
779949: 33 c5 xor eax,ebp
77994b: 89 45 f0 mov DWORD PTR [ebp-0x10],eax
77994e: 56 push esi
77994f: 50 push eax
779950: 8d 45 f4 lea eax,[ebp-0xc]
779953: 64 a3 00 00 00 00 mov fs:0x0,eax
779959: 8b f1 mov esi,ecx
77995b: 8b 86 8c 00 00 00 mov eax,DWORD PTR [esi+0x8c]
779961: 85 c0 test eax,eax
779963: 75 0c jne 0x779971
779965: 68 34 24 a2 00 push 0xa22434
77996a: e8 e1 05 14 00 call 0x8b9f50
77996f: eb 7e jmp 0x7799ef
779971: 50 push eax
779972: e8 09 cc c9 ff call 0x416580
779977: 83 c4 04 add esp,0x4
77997a: 85 c0 test eax,eax
77997c: 74 0c je 0x77998a
77997e: 68 f8 23 a2 00 push 0xa223f8
779983: e8 58 08 14 00 call 0x8ba1e0
779988: eb 65 jmp 0x7799ef
77998a: e8 d1 58 dc ff call 0x53f260
77998f: c7 45 e8 0f 00 00 00 mov DWORD PTR [ebp-0x18],0xf
779996: c7 45 e4 00 00 00 00 mov DWORD PTR [ebp-0x1c],0x0
77999d: c6 45 d4 00 mov BYTE PTR [ebp-0x2c],0x0
7799a1: 8d 4d d4 lea ecx,[ebp-0x2c]
7799a4: 51 push ecx
7799a5: 50 push eax
7799a6: c7 45 fc 00 00 00 00 mov DWORD PTR [ebp-0x4],0x0
7799ad: e8 fe 52 dc ff call 0x53ecb0
7799b2: 8b 45 d4 mov eax,DWORD PTR [ebp-0x2c]
7799b5: 83 c4 08 add esp,0x8
7799b8: 83 7d e8 10 cmp DWORD PTR [ebp-0x18],0x10
7799bc: 73 03 jae 0x7799c1
7799be: 8d 45 d4 lea eax,[ebp-0x2c]
7799c1: 8b 96 8c 00 00 00 mov edx,DWORD PTR [esi+0x8c]
7799c7: 6a 00 push 0x0
7799c9: 56 push esi
7799ca: 68 a0 8d 77 00 push 0x778da0
7799cf: 68 e0 ea 76 00 push 0x76eae0
7799d4: 6a 00 push 0x0
7799d6: 50 push eax
7799d7: 52 push edx
7799d8: e8 f3 d7 c9 ff call 0x4171d0
7799dd: 83 c4 1c add esp,0x1c
7799e0: 83 7d e8 10 cmp DWORD PTR [ebp-0x18],0x10
7799e4: 72 0c jb 0x7799f2
7799e6: 8b 45 d4 mov eax,DWORD PTR [ebp-0x2c]
7799e9: 50 push eax
7799ea: e8 bb b5 1a 00 call 0x924faa
7799ef: 83 c4 04 add esp,0x4
7799f2: 8b 4d f4 mov ecx,DWORD PTR [ebp-0xc]
7799f5: 64 89 0d 00 00 00 00 mov DWORD PTR fs:0x0,ecx
7799fc: 59 pop ecx
7799fd: 5e pop esi
7799fe: 8b 4d f0 mov ecx,DWORD PTR [ebp-0x10]
779a01: 33 cd xor ecx,ebp
779a03: e8 7a b3 1a 00 call 0x924d82
779a08: 8b e5 mov esp,ebp
779a0a: 5d pop ebp
779a0b: c3 ret
779a0c: cc int3
779a0d: cc int3
779a0e: cc int3
779a0f: cc int3
779a10: 53 push ebx
779a11: 56 push esi
779a12: 8b f1 mov esi,ecx
779a14: 57 push edi
779a15: 8b be 24 01 00 00 mov edi,DWORD PTR [esi+0x124]
779a1b: 33 db xor ebx,ebx
779a1d: 3b fb cmp edi,ebx
779a1f: 74 10 je 0x779a31
779a21: 8b cf mov ecx,edi
779a23: e8 call 0x770450

View file

@ -0,0 +1,39 @@
/home/alex/sots-re/dumps/sots.exe: file format pei-i386
Disassembly of section .text:
00629580 <.text+0x228580>:
629580: 57 push edi
629581: 8b f9 mov edi,ecx
629583: 83 3f 00 cmp DWORD PTR [edi],0x0
629586: 74 36 je 0x6295be
629588: 53 push ebx
629589: 56 push esi
62958a: ff 15 2c d1 9d 00 call DWORD PTR ds:0x9dd12c
629590: 8b 5f 04 mov ebx,DWORD PTR [edi+0x4]
629593: 8b 37 mov esi,DWORD PTR [edi]
629595: 3b f3 cmp esi,ebx
629597: 74 18 je 0x6295b1
629599: 8d a4 24 00 00 00 00 lea esp,[esp+0x0]
6295a0: 8b 06 mov eax,DWORD PTR [esi]
6295a2: 8b 10 mov edx,DWORD PTR [eax]
6295a4: 6a 00 push 0x0
6295a6: 8b ce mov ecx,esi
6295a8: ff d2 call edx
6295aa: 83 c6 74 add esi,0x74
6295ad: 3b f3 cmp esi,ebx
6295af: 75 ef jne 0x6295a0
6295b1: 8b 07 mov eax,DWORD PTR [edi]
6295b3: 50 push eax
6295b4: e8 f1 b9 2f 00 call 0x924faa
6295b9: 83 c4 04 add esp,0x4
6295bc: 5e pop esi
6295bd: 5b pop ebx
6295be: 33 c0 xor eax,eax
6295c0: 89 07 mov DWORD PTR [edi],eax
6295c2: 89 47 04 mov DWORD PTR [edi+0x4],eax
6295c5: 89 47 08 mov DWORD PTR [edi+0x8],eax
6295c8: 5f pop edi
6295c9: c3 ret

View file

@ -0,0 +1,43 @@
/home/alex/sots-re/dumps/sots.exe: file format pei-i386
Disassembly of section .text:
00629580 <.text+0x228580>:
629580: 57 push edi
629581: 8b f9 mov edi,ecx
629583: 83 3f 00 cmp DWORD PTR [edi],0x0
629586: 74 36 je 0x6295be
629588: 53 push ebx
629589: 56 push esi
62958a: ff 15 2c d1 9d 00 call DWORD PTR ds:0x9dd12c
629590: 8b 5f 04 mov ebx,DWORD PTR [edi+0x4]
629593: 8b 37 mov esi,DWORD PTR [edi]
629595: 3b f3 cmp esi,ebx
629597: 74 18 je 0x6295b1
629599: 8d a4 24 00 00 00 00 lea esp,[esp+0x0]
6295a0: 8b 06 mov eax,DWORD PTR [esi]
6295a2: 8b 10 mov edx,DWORD PTR [eax]
6295a4: 6a 00 push 0x0
6295a6: 8b ce mov ecx,esi
6295a8: ff d2 call edx
6295aa: 83 c6 74 add esi,0x74
6295ad: 3b f3 cmp esi,ebx
6295af: 75 ef jne 0x6295a0
6295b1: 8b 07 mov eax,DWORD PTR [edi]
6295b3: 50 push eax
6295b4: e8 f1 b9 2f 00 call 0x924faa
6295b9: 83 c4 04 add esp,0x4
6295bc: 5e pop esi
6295bd: 5b pop ebx
6295be: 33 c0 xor eax,eax
6295c0: 89 07 mov DWORD PTR [edi],eax
6295c2: 89 47 04 mov DWORD PTR [edi+0x4],eax
6295c5: 89 47 08 mov DWORD PTR [edi+0x8],eax
6295c8: 5f pop edi
6295c9: c3 ret
6295ca: cc int3
6295cb: cc int3
6295cc: cc int3
6295cd: cc int3

View file

@ -0,0 +1,85 @@
/home/alex/sots-re/dumps/sots.exe: file format pei-i386
Disassembly of section .text:
00884cb0 <.text+0x483cb0>:
884cb0: 55 push ebp
884cb1: 8b ec mov ebp,esp
884cb3: 6a ff push 0xffffffff
884cb5: 68 72 0b 98 00 push 0x980b72
884cba: 64 a1 00 00 00 00 mov eax,fs:0x0
884cc0: 50 push eax
884cc1: 51 push ecx
884cc2: 56 push esi
884cc3: 57 push edi
884cc4: a1 78 8b af 00 mov eax,ds:0xaf8b78
884cc9: 33 c5 xor eax,ebp
884ccb: 50 push eax
884ccc: 8d 45 f4 lea eax,[ebp-0xc]
884ccf: 64 a3 00 00 00 00 mov fs:0x0,eax
884cd5: 8b f9 mov edi,ecx
884cd7: 8b 4f 04 mov ecx,DWORD PTR [edi+0x4]
884cda: 8b 75 08 mov esi,DWORD PTR [ebp+0x8]
884cdd: 3b f1 cmp esi,ecx
884cdf: 73 59 jae 0x884d3a
884ce1: 8b 07 mov eax,DWORD PTR [edi]
884ce3: 3b c6 cmp eax,esi
884ce5: 77 53 ja 0x884d3a
884ce7: 2b f0 sub esi,eax
884ce9: b8 ab aa aa 2a mov eax,0x2aaaaaab
884cee: f7 ee imul esi
884cf0: c1 fa 02 sar edx,0x2
884cf3: 8b f2 mov esi,edx
884cf5: c1 ee 1f shr esi,0x1f
884cf8: 03 f2 add esi,edx
884cfa: 3b 4f 08 cmp ecx,DWORD PTR [edi+0x8]
884cfd: 75 09 jne 0x884d08
884cff: 6a 01 push 0x1
884d01: 8b cf mov ecx,edi
884d03: e8 98 f4 ff ff call 0x8841a0
884d08: 8b 0f mov ecx,DWORD PTR [edi]
884d0a: 8d 04 76 lea eax,[esi+esi*2]
884d0d: 8d 0c c1 lea ecx,[ecx+eax*8]
884d10: 8b 47 04 mov eax,DWORD PTR [edi+0x4]
884d13: 89 45 08 mov DWORD PTR [ebp+0x8],eax
884d16: 89 45 f0 mov DWORD PTR [ebp-0x10],eax
884d19: c7 45 fc 00 00 00 00 mov DWORD PTR [ebp-0x4],0x0
884d20: 85 c0 test eax,eax
884d22: 74 54 je 0x884d78
884d24: c7 00 7c f0 a0 00 mov DWORD PTR [eax],0xa0f07c
884d2a: 8b 51 04 mov edx,DWORD PTR [ecx+0x4]
884d2d: 83 c1 08 add ecx,0x8
884d30: c6 45 fc 01 mov BYTE PTR [ebp-0x4],0x1
884d34: 89 50 04 mov DWORD PTR [eax+0x4],edx
884d37: 51 push ecx
884d38: eb 36 jmp 0x884d70
884d3a: 3b 4f 08 cmp ecx,DWORD PTR [edi+0x8]
884d3d: 75 09 jne 0x884d48
884d3f: 6a 01 push 0x1
884d41: 8b cf mov ecx,edi
884d43: e8 58 f4 ff ff call 0x8841a0
884d48: 8b 47 04 mov eax,DWORD PTR [edi+0x4]
884d4b: 89 45 08 mov DWORD PTR [ebp+0x8],eax
884d4e: 89 45 f0 mov DWORD PTR [ebp-0x10],eax
884d51: c7 45 fc 02 00 00 00 mov DWORD PTR [ebp-0x4],0x2
884d58: 85 c0 test eax,eax
884d5a: 74 1c je 0x884d78
884d5c: c7 00 7c f0 a0 00 mov DWORD PTR [eax],0xa0f07c
884d62: 8b 4e 04 mov ecx,DWORD PTR [esi+0x4]
884d65: 83 c6 08 add esi,0x8
884d68: c6 45 fc 03 mov BYTE PTR [ebp-0x4],0x3
884d6c: 89 48 04 mov DWORD PTR [eax+0x4],ecx
884d6f: 56 push esi
884d70: 8d 48 08 lea ecx,[eax+0x8]
884d73: e8 d8 4a ef ff call 0x779850
884d78: 83 47 04 18 add DWORD PTR [edi+0x4],0x18
884d7c: 8b 4d f4 mov ecx,DWORD PTR [ebp-0xc]
884d7f: 64 89 0d 00 00 00 00 mov DWORD PTR fs:0x0,ecx
884d86: 59 pop ecx
884d87: 5f pop edi
884d88: 5e pop esi
884d89: 8b e5 mov esp,ebp
884d8b: 5d pop ebp
884d8c: c2 04 00 ret 0x4

View file

@ -0,0 +1,88 @@
/home/alex/sots-re/dumps/sots.exe: file format pei-i386
Disassembly of section .text:
00884cb0 <.text+0x483cb0>:
884cb0: 55 push ebp
884cb1: 8b ec mov ebp,esp
884cb3: 6a ff push 0xffffffff
884cb5: 68 72 0b 98 00 push 0x980b72
884cba: 64 a1 00 00 00 00 mov eax,fs:0x0
884cc0: 50 push eax
884cc1: 51 push ecx
884cc2: 56 push esi
884cc3: 57 push edi
884cc4: a1 78 8b af 00 mov eax,ds:0xaf8b78
884cc9: 33 c5 xor eax,ebp
884ccb: 50 push eax
884ccc: 8d 45 f4 lea eax,[ebp-0xc]
884ccf: 64 a3 00 00 00 00 mov fs:0x0,eax
884cd5: 8b f9 mov edi,ecx
884cd7: 8b 4f 04 mov ecx,DWORD PTR [edi+0x4]
884cda: 8b 75 08 mov esi,DWORD PTR [ebp+0x8]
884cdd: 3b f1 cmp esi,ecx
884cdf: 73 59 jae 0x884d3a
884ce1: 8b 07 mov eax,DWORD PTR [edi]
884ce3: 3b c6 cmp eax,esi
884ce5: 77 53 ja 0x884d3a
884ce7: 2b f0 sub esi,eax
884ce9: b8 ab aa aa 2a mov eax,0x2aaaaaab
884cee: f7 ee imul esi
884cf0: c1 fa 02 sar edx,0x2
884cf3: 8b f2 mov esi,edx
884cf5: c1 ee 1f shr esi,0x1f
884cf8: 03 f2 add esi,edx
884cfa: 3b 4f 08 cmp ecx,DWORD PTR [edi+0x8]
884cfd: 75 09 jne 0x884d08
884cff: 6a 01 push 0x1
884d01: 8b cf mov ecx,edi
884d03: e8 98 f4 ff ff call 0x8841a0
884d08: 8b 0f mov ecx,DWORD PTR [edi]
884d0a: 8d 04 76 lea eax,[esi+esi*2]
884d0d: 8d 0c c1 lea ecx,[ecx+eax*8]
884d10: 8b 47 04 mov eax,DWORD PTR [edi+0x4]
884d13: 89 45 08 mov DWORD PTR [ebp+0x8],eax
884d16: 89 45 f0 mov DWORD PTR [ebp-0x10],eax
884d19: c7 45 fc 00 00 00 00 mov DWORD PTR [ebp-0x4],0x0
884d20: 85 c0 test eax,eax
884d22: 74 54 je 0x884d78
884d24: c7 00 7c f0 a0 00 mov DWORD PTR [eax],0xa0f07c
884d2a: 8b 51 04 mov edx,DWORD PTR [ecx+0x4]
884d2d: 83 c1 08 add ecx,0x8
884d30: c6 45 fc 01 mov BYTE PTR [ebp-0x4],0x1
884d34: 89 50 04 mov DWORD PTR [eax+0x4],edx
884d37: 51 push ecx
884d38: eb 36 jmp 0x884d70
884d3a: 3b 4f 08 cmp ecx,DWORD PTR [edi+0x8]
884d3d: 75 09 jne 0x884d48
884d3f: 6a 01 push 0x1
884d41: 8b cf mov ecx,edi
884d43: e8 58 f4 ff ff call 0x8841a0
884d48: 8b 47 04 mov eax,DWORD PTR [edi+0x4]
884d4b: 89 45 08 mov DWORD PTR [ebp+0x8],eax
884d4e: 89 45 f0 mov DWORD PTR [ebp-0x10],eax
884d51: c7 45 fc 02 00 00 00 mov DWORD PTR [ebp-0x4],0x2
884d58: 85 c0 test eax,eax
884d5a: 74 1c je 0x884d78
884d5c: c7 00 7c f0 a0 00 mov DWORD PTR [eax],0xa0f07c
884d62: 8b 4e 04 mov ecx,DWORD PTR [esi+0x4]
884d65: 83 c6 08 add esi,0x8
884d68: c6 45 fc 03 mov BYTE PTR [ebp-0x4],0x3
884d6c: 89 48 04 mov DWORD PTR [eax+0x4],ecx
884d6f: 56 push esi
884d70: 8d 48 08 lea ecx,[eax+0x8]
884d73: e8 d8 4a ef ff call 0x779850
884d78: 83 47 04 18 add DWORD PTR [edi+0x4],0x18
884d7c: 8b 4d f4 mov ecx,DWORD PTR [ebp-0xc]
884d7f: 64 89 0d 00 00 00 00 mov DWORD PTR fs:0x0,ecx
884d86: 59 pop ecx
884d87: 5f pop edi
884d88: 5e pop esi
884d89: 8b e5 mov esp,ebp
884d8b: 5d pop ebp
884d8c: c2 04 00 ret 0x4
884d8f: cc int3
884d90: 55 push ebp
884d91: 8b ec mov ebp,esp

View file

@ -0,0 +1,83 @@
/home/alex/sots-re/dumps/sots.exe: file format pei-i386
Disassembly of section .text:
00885380 <.text+0x484380>:
885380: 55 push ebp
885381: 8b ec mov ebp,esp
885383: 6a ff push 0xffffffff
885385: 68 30 af 99 00 push 0x99af30
88538a: 64 a1 00 00 00 00 mov eax,fs:0x0
885390: 50 push eax
885391: 83 ec 18 sub esp,0x18
885394: 53 push ebx
885395: 56 push esi
885396: 57 push edi
885397: a1 78 8b af 00 mov eax,ds:0xaf8b78
88539c: 33 c5 xor eax,ebp
88539e: 50 push eax
88539f: 8d 45 f4 lea eax,[ebp-0xc]
8853a2: 64 a3 00 00 00 00 mov fs:0x0,eax
8853a8: 8b f1 mov esi,ecx
8853aa: 8b 56 08 mov edx,DWORD PTR [esi+0x8]
8853ad: 2b 56 04 sub edx,DWORD PTR [esi+0x4]
8853b0: 8d 4e 04 lea ecx,[esi+0x4]
8853b3: b8 ab aa aa 2a mov eax,0x2aaaaaab
8853b8: f7 ea imul edx
8853ba: c1 fa 02 sar edx,0x2
8853bd: 8b c2 mov eax,edx
8853bf: c1 e8 1f shr eax,0x1f
8853c2: 33 db xor ebx,ebx
8853c4: 03 c2 add eax,edx
8853c6: 33 ff xor edi,edi
8853c8: 3b c3 cmp eax,ebx
8853ca: 7e 30 jle 0x8853fc
8853cc: 8b 11 mov edx,DWORD PTR [ecx]
8853ce: 8b ff mov edi,edi
8853d0: 8b 5d 08 mov ebx,DWORD PTR [ebp+0x8]
8853d3: 39 5a 04 cmp DWORD PTR [edx+0x4],ebx
8853d6: 75 02 jne 0x8853da
8853d8: 8b fa mov edi,edx
8853da: 83 c2 18 add edx,0x18
8853dd: 48 dec eax
8853de: 75 f0 jne 0x8853d0
8853e0: 33 db xor ebx,ebx
8853e2: 3b fb cmp edi,ebx
8853e4: 74 16 je 0x8853fc
8853e6: 8b c7 mov eax,edi
8853e8: 8b 4d f4 mov ecx,DWORD PTR [ebp-0xc]
8853eb: 64 89 0d 00 00 00 00 mov DWORD PTR fs:0x0,ecx
8853f2: 59 pop ecx
8853f3: 5f pop edi
8853f4: 5e pop esi
8853f5: 5b pop ebx
8853f6: 8b e5 mov esp,ebp
8853f8: 5d pop ebp
8853f9: c2 04 00 ret 0x4
8853fc: c7 45 dc 7c f0 a0 00 mov DWORD PTR [ebp-0x24],0xa0f07c
885403: 89 5d e4 mov DWORD PTR [ebp-0x1c],ebx
885406: 89 5d e8 mov DWORD PTR [ebp-0x18],ebx
885409: 89 5d ec mov DWORD PTR [ebp-0x14],ebx
88540c: 8d 45 dc lea eax,[ebp-0x24]
88540f: 50 push eax
885410: 89 5d fc mov DWORD PTR [ebp-0x4],ebx
885413: e8 98 f8 ff ff call 0x884cb0
885418: 8d 4d e4 lea ecx,[ebp-0x1c]
88541b: c7 45 fc 01 00 00 00 mov DWORD PTR [ebp-0x4],0x1
885422: e8 59 41 da ff call 0x629580
885427: 8b 46 08 mov eax,DWORD PTR [esi+0x8]
88542a: 8b 4d 08 mov ecx,DWORD PTR [ebp+0x8]
88542d: 89 48 ec mov DWORD PTR [eax-0x14],ecx
885430: 8b 46 08 mov eax,DWORD PTR [esi+0x8]
885433: 83 e8 18 sub eax,0x18
885436: 8b 4d f4 mov ecx,DWORD PTR [ebp-0xc]
885439: 64 89 0d 00 00 00 00 mov DWORD PTR fs:0x0,ecx
885440: 59 pop ecx
885441: 5f pop edi
885442: 5e pop esi
885443: 5b pop ebx
885444: 8b e5 mov esp,ebp
885446: 5d pop ebp
885447: c2 04 00 ret 0x4

View file

@ -0,0 +1,87 @@
/home/alex/sots-re/dumps/sots.exe: file format pei-i386
Disassembly of section .text:
00885380 <.text+0x484380>:
885380: 55 push ebp
885381: 8b ec mov ebp,esp
885383: 6a ff push 0xffffffff
885385: 68 30 af 99 00 push 0x99af30
88538a: 64 a1 00 00 00 00 mov eax,fs:0x0
885390: 50 push eax
885391: 83 ec 18 sub esp,0x18
885394: 53 push ebx
885395: 56 push esi
885396: 57 push edi
885397: a1 78 8b af 00 mov eax,ds:0xaf8b78
88539c: 33 c5 xor eax,ebp
88539e: 50 push eax
88539f: 8d 45 f4 lea eax,[ebp-0xc]
8853a2: 64 a3 00 00 00 00 mov fs:0x0,eax
8853a8: 8b f1 mov esi,ecx
8853aa: 8b 56 08 mov edx,DWORD PTR [esi+0x8]
8853ad: 2b 56 04 sub edx,DWORD PTR [esi+0x4]
8853b0: 8d 4e 04 lea ecx,[esi+0x4]
8853b3: b8 ab aa aa 2a mov eax,0x2aaaaaab
8853b8: f7 ea imul edx
8853ba: c1 fa 02 sar edx,0x2
8853bd: 8b c2 mov eax,edx
8853bf: c1 e8 1f shr eax,0x1f
8853c2: 33 db xor ebx,ebx
8853c4: 03 c2 add eax,edx
8853c6: 33 ff xor edi,edi
8853c8: 3b c3 cmp eax,ebx
8853ca: 7e 30 jle 0x8853fc
8853cc: 8b 11 mov edx,DWORD PTR [ecx]
8853ce: 8b ff mov edi,edi
8853d0: 8b 5d 08 mov ebx,DWORD PTR [ebp+0x8]
8853d3: 39 5a 04 cmp DWORD PTR [edx+0x4],ebx
8853d6: 75 02 jne 0x8853da
8853d8: 8b fa mov edi,edx
8853da: 83 c2 18 add edx,0x18
8853dd: 48 dec eax
8853de: 75 f0 jne 0x8853d0
8853e0: 33 db xor ebx,ebx
8853e2: 3b fb cmp edi,ebx
8853e4: 74 16 je 0x8853fc
8853e6: 8b c7 mov eax,edi
8853e8: 8b 4d f4 mov ecx,DWORD PTR [ebp-0xc]
8853eb: 64 89 0d 00 00 00 00 mov DWORD PTR fs:0x0,ecx
8853f2: 59 pop ecx
8853f3: 5f pop edi
8853f4: 5e pop esi
8853f5: 5b pop ebx
8853f6: 8b e5 mov esp,ebp
8853f8: 5d pop ebp
8853f9: c2 04 00 ret 0x4
8853fc: c7 45 dc 7c f0 a0 00 mov DWORD PTR [ebp-0x24],0xa0f07c
885403: 89 5d e4 mov DWORD PTR [ebp-0x1c],ebx
885406: 89 5d e8 mov DWORD PTR [ebp-0x18],ebx
885409: 89 5d ec mov DWORD PTR [ebp-0x14],ebx
88540c: 8d 45 dc lea eax,[ebp-0x24]
88540f: 50 push eax
885410: 89 5d fc mov DWORD PTR [ebp-0x4],ebx
885413: e8 98 f8 ff ff call 0x884cb0
885418: 8d 4d e4 lea ecx,[ebp-0x1c]
88541b: c7 45 fc 01 00 00 00 mov DWORD PTR [ebp-0x4],0x1
885422: e8 59 41 da ff call 0x629580
885427: 8b 46 08 mov eax,DWORD PTR [esi+0x8]
88542a: 8b 4d 08 mov ecx,DWORD PTR [ebp+0x8]
88542d: 89 48 ec mov DWORD PTR [eax-0x14],ecx
885430: 8b 46 08 mov eax,DWORD PTR [esi+0x8]
885433: 83 e8 18 sub eax,0x18
885436: 8b 4d f4 mov ecx,DWORD PTR [ebp-0xc]
885439: 64 89 0d 00 00 00 00 mov DWORD PTR fs:0x0,ecx
885440: 59 pop ecx
885441: 5f pop edi
885442: 5e pop esi
885443: 5b pop ebx
885444: 8b e5 mov esp,ebp
885446: 5d pop ebp
885447: c2 04 00 ret 0x4
88544a: cc int3
88544b: cc int3
88544c: cc int3
88544d: cc int3

View file

@ -0,0 +1,68 @@
# Independent correction verification plan
Session `run-ee78b8773688ca09f8046e21`; actor `research-abi-correction-verifier`;
model `openai/gpt-5.6-sol`. This plan predates the verifier capture. It covers static
reproduction and does not authorize game, allocator, VM, Ghidra, or build-host execution.
## Required identities and positive execution
The assigned paired source manifests must rehash to engine
`ccd8e02083e8d2e2b3e97976ace2273c8f924dfc02a39e919004eaf3544c50fd` at HEAD
`7741d42fc5e4e761e6449bdaf0e4a61d00036a23` and RE
`6696fd5201e144843617cbf6d78b41b5287ad5dcc9fa1e8aaa861d52b64e72e8` at HEAD
`3bfde5a70d874a723e797a695bbd847fd82c0aa7`. The input must be 7,898,624-byte
`dumps/sots.exe` SHA-256 `970b7de729956a53094c7eb98aba4270aee98e2fed5daf0d39e290013c90c841`.
The instrument must be 373,888-byte `/usr/bin/objdump` SHA-256
`1eaaef2e7f57c4c7f69115c495e2466f5a8c8e5f3bc42221d092382f30f9d4cd`, GNU
objdump 2.38. Every command must return zero, emit nonempty stdout and empty stderr.
## Falsifiers
1. Any source, binary, tool, command boundary, byte count, or digest mismatch fails
reproduction; a decoded-looking listing does not override provenance failure.
2. Any write to `[EBP-0x20]` in get/create before the call at `0x00885413` falsifies the
corrected uninitialized-in-this-routine claim. Absence of a write does not prove a runtime
value, randomness, or allocator safety.
3. Failure of append to copy source `+4` to destination `+4`, or advancement of `_Mylast`
before nested copy returns, falsifies the claimed append ordering.
4. A final requested-turn store before temporary nested cleanup, or a returned pointer other
than `_Mylast-0x18`, falsifies the usable miss-path postcondition.
5. A nested-copy destination not initialized to three null pointers, allocation on its empty
branch, failure to expose a nonempty allocation/range-copy branch, or a stride other than
`0x74` falsifies the nested ownership interpretation.
6. A null nested-vector destructor path that destroys/frees, or a nonnull path lacking
per-element virtual destruction, `0x00924faa` free, and final three-pointer zeroing,
falsifies cleanup accounting.
7. Zero commands, unexpected skips, truncated terminal instructions, or fewer than all four
declared windows fails the package even if surviving hashes match.
## Required branch exposures and distinct states
* Get/create: empty outer vector; nonempty/no match; one match; duplicate matches selecting the
last; hit early return with no construction; and miss construction through cleanup/final store.
These are static control-flow states, not executed runtime fixtures.
* Outer append: spare-capacity external-source copy and full-capacity growth dispatch; the
source-inside-vector branch must be distinguished where the window exposes it. No allocation
failure is claimed executed.
* Nested copy: empty source (no allocation) versus nonempty source (allocation and `0x74`-stride
range copy), plus visible unwind edge without claiming a thrown execution.
* Nested destruction: null first pointer versus nonnull element loop/free, including final
pointer-zero state.
* Ordering: incoming transient scalar copy, nested copy completion, outer `_Mylast` advance,
temporary nested cleanup, requested-turn publication, then returned last element.
## Held-out challenge / ablation
In addition to byte-for-byte reproduction of the four handoff commands, capture each window with
its stop address widened by four bytes. Require every original stream's instruction rows to be an
exact prefix of the widened stream's rows and inspect the first added instruction. This challenges
the assumption that exact stop boundaries did not truncate a terminal instruction, the provenance
failure that invalidated earlier packages. Independently enumerate get/create stack-memory writes
through `0x00885413`; do not infer the answer from report prose.
## Acceptance limits
Success is an **independent static full compare** of four windows plus a static boundary ablation.
It is not original-game runtime comparison, integrated replay, live allocator safety, failure-path
execution, or independent replacement acceptance. Missing full/spare live fixtures, nonempty live
nested-copy state, transient observation, and induced unwind remain residuals.